7.8
CVE-2024-46833
- EPSS 0.23%
- Veröffentlicht 27.09.2024 13:15:15
- Zuletzt bearbeitet 09.10.2024 15:54:38
- Erkennungen
net: hns3: void array out of bound when loop tnl_num
In the Linux kernel, the following vulnerability has been resolved: net: hns3: void array out of bound when loop tnl_num When query reg inf of SSU, it loops tnl_num times. However, tnl_num comes from hardware and the length of array is a fixed value. To void array out of bound, make sure the loop time is not greater than the length of array
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 6.10.10
Linux ≫ Linux Kernel Version 6.11 Update rc1
Linux ≫ Linux Kernel Version 6.11 Update rc2
Linux ≫ Linux Kernel Version 6.11 Update rc3
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.136 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-129 Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
https://git.kernel.org/stable/c/86db7bfb06704ef17340eeae71c832f21cfce35c
https://git.kernel.org/stable/c/c33a9806dc806bcb4a31dc71fb06979219181ad4