7.8
CVE-2024-53106
- EPSS 0.24%
- Veröffentlicht 02.12.2024 14:15:11
- Zuletzt bearbeitet 04.08.2026 11:21:53
- Erkennungen
ima: fix buffer overrun in ima_eventdigest_init_common
In the Linux kernel, the following vulnerability has been resolved: ima: fix buffer overrun in ima_eventdigest_init_common Function ima_eventdigest_init() calls ima_eventdigest_init_common() with HASH_ALGO__LAST which is then used to access the array hash_digest_size[] leading to buffer overrun. Have a conditional statement to handle this.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.19.1 < 6.1.119
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.63
Linux ≫ Linux Kernel Version >= 6.7 < 6.11.10
Linux ≫ Linux Kernel Version 5.19 Update -
Linux ≫ Linux Kernel Version 5.19 Update rc7
Linux ≫ Linux Kernel Version 5.19 Update rc8
Linux ≫ Linux Kernel Version 6.12 Update rc1
Linux ≫ Linux Kernel Version 6.12 Update rc2
Linux ≫ Linux Kernel Version 6.12 Update rc3
Linux ≫ Linux Kernel Version 6.12 Update rc4
Linux ≫ Linux Kernel Version 6.12 Update rc5
Linux ≫ Linux Kernel Version 6.12 Update rc6
Linux ≫ Linux Kernel Version 6.12 Update rc7
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.152 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| CISA-ADP | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.3 | 1.8 | 5.5 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://git.kernel.org/stable/c/1ecf0df5205cfb0907eb7984b8671257965a5232
https://git.kernel.org/stable/c/8a84765c62cc0469864e2faee43aae253ad16082
https://git.kernel.org/stable/c/923168a0631bc42fffd55087b337b1b6c54dcff5
https://git.kernel.org/stable/c/e01aae58e818503f2ffcd34c6f7dc6f90af1057e
https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html