5.5
CVE-2024-53681
- EPSS 0.19%
- Veröffentlicht 15.01.2025 13:15:10
- Zuletzt bearbeitet 15.10.2025 19:59:15
- Erkennungen
nvmet: Don't overflow subsysnqn
In the Linux kernel, the following vulnerability has been resolved: nvmet: Don't overflow subsysnqn nvmet_root_discovery_nqn_store treats the subsysnqn string like a fixed size buffer, even though it is dynamically allocated to the size of the string. Create a new string with kstrndup instead of using the old buffer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.9.1 < 6.12.9
Linux ≫ Linux Kernel Version 6.9 Update -
Linux ≫ Linux Kernel Version 6.9 Update rc3
Linux ≫ Linux Kernel Version 6.9 Update rc4
Linux ≫ Linux Kernel Version 6.9 Update rc5
Linux ≫ Linux Kernel Version 6.9 Update rc6
Linux ≫ Linux Kernel Version 6.9 Update rc7
Linux ≫ Linux Kernel Version 6.13 Update rc1
Linux ≫ Linux Kernel Version 6.13 Update rc2
Linux ≫ Linux Kernel Version 6.13 Update rc3
Linux ≫ Linux Kernel Version 6.13 Update rc4
Linux ≫ Linux Kernel Version 6.13 Update rc5
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.087 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
https://git.kernel.org/stable/c/4db3d750ac7e894278ef1cb1c53cc7d883060496
https://git.kernel.org/stable/c/86645d8d062af3fdcbdaa0a289b95de55bca827d