5.7

CVE-2024-53922

An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSamsung
≫
Produkt Exynos 8890 firmware
Default Statusunaffected
Version V7
Status affected
Version V9
Status affected
Version V920
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.053
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
MITRE 5.7 1.4 4.2
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
CWE-1284 Improper Validation of Specified Quantity in Input

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

https://semiconductor.samsung.com/support/quality-support/product-security-updates/
https://diconium.com/de/blog/cybersecurity/hunting-bugs-in-linux-kernel-with-kasan
https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-53922/