5.5

CVE-2024-41026

mmc: davinci_mmc: Prevent transmitted data size from exceeding sgm's length

In the Linux kernel, the following vulnerability has been resolved:

mmc: davinci_mmc: Prevent transmitted data size from exceeding sgm's length

No check is done on the size of the data to be transmiited. This causes
a kernel panic when this size exceeds the sg_miter's length.

Limit the number of transmitted bytes to sgm->length.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.9 < 6.9.10
Linux ≫ Linux Kernel Version 6.10 Update rc1
Linux ≫ Linux Kernel Version 6.10 Update rc2
Linux ≫ Linux Kernel Version 6.10 Update rc3
Linux ≫ Linux Kernel Version 6.10 Update rc4
Linux ≫ Linux Kernel Version 6.10 Update rc5
Linux ≫ Linux Kernel Version 6.10 Update rc6
Linux ≫ Linux Kernel Version 6.10 Update rc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.174
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/16198eef11c1929374381d7f6271b4bf6aa44615
Patch
https://git.kernel.org/stable/c/c561c4ecce712f94b442db5960e281f13b28df2e
Patch