5.5

CVE-2024-50259

netdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write()

In the Linux kernel, the following vulnerability has been resolved:

netdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write()

This was found by a static analyzer.
We should not forget the trailing zero after copy_from_user()
if we will further do some string operations, sscanf() in this
case. Adding a trailing zero will ensure that the function
performs properly.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.13 < 5.15.171
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.116
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.60
Linux ≫ Linux Kernel Version >= 6.7 < 6.11.7
Linux ≫ Linux Kernel Version 6.12 Update rc1
Linux ≫ Linux Kernel Version 6.12 Update rc2
Linux ≫ Linux Kernel Version 6.12 Update rc3
Linux ≫ Linux Kernel Version 6.12 Update rc4
Linux ≫ Linux Kernel Version 6.12 Update rc5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.121
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://git.kernel.org/stable/c/27bd7a742e171362c9eb52ad5d1d71d3321f949f
Patch
https://git.kernel.org/stable/c/4ce1f56a1eaced2523329bef800d004e30f2f76c
Patch
https://git.kernel.org/stable/c/6a604877160fe5ab2e1985d5ce1ba6a61abe0693
Patch
https://git.kernel.org/stable/c/bcba86e03b3aac361ea671672cf48eed11f9011c
Patch
https://git.kernel.org/stable/c/c2150f666c6fc301d5d1643ed0f92251f1a0ff0d
Patch
https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html