CVE-2024-36978
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in multiq_tune() q->bands will be assigned to qopt->bands to execute subsequent code logic after kmalloc. So the old q->bands should not be used in kmalloc. Otherwise, an out-of-bounds write will occur.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.03%• Percentile: 9%
Techniques & Countermeasures
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- linux•linux
≥ c2999f7fb05b87da4060e38150c70fa46794d82b, < d5d9d241786f49ae7cbc08e7fc95a115e9d80f3d | ≥ c2999f7fb05b87da4060e38150c70fa46794d82b, < 52b1aa07cda6a199cd6754d3798c7759023bc70f | ≥ c2999f7fb05b87da4060e38150c70fa46794d82b, < 598572c64287aee0b75bbba4e2881496878860f3 | ≥ c2999f7fb05b87da4060e38150c70fa46794d82b, < 0f208fad86631e005754606c3ec80c0d44a11882 | ≥ c2999f7fb05b87da4060e38150c70fa46794d82b, < 54c2c171c11a798fe887b3ff72922aa9d1411c1e | ≥ c2999f7fb05b87da4060e38150c70fa46794d82b, < d6fb5110e8722bc00748f22caeb650fe4672f129 | ≥ c2999f7fb05b87da4060e38150c70fa46794d82b, < affc18fdc694190ca7575b9a86632a73b9fe043d | 5.4
- linux•linux_kernel
≥ 5.4, < 5.4.279 | ≥ 5.5, < 5.10.221 | ≥ 5.11, < 5.15.162 | ≥ 5.16, < 6.1.95 | ≥ 6.2, < 6.6.35 | ≥ 6.7, < 6.9.6 | 6.10:rc1 | 6.10:rc2
References (11)
- https://git.kernel.org/stable/c/d5d9d241786f49ae7cbc08e7fc95a115e9d80f3d
- https://git.kernel.org/stable/c/52b1aa07cda6a199cd6754d3798c7759023bc70f
- https://git.kernel.org/stable/c/598572c64287aee0b75bbba4e2881496878860f3
- https://git.kernel.org/stable/c/0f208fad86631e005754606c3ec80c0d44a11882
- https://git.kernel.org/stable/c/54c2c171c11a798fe887b3ff72922aa9d1411c1e
- https://git.kernel.org/stable/c/d6fb5110e8722bc00748f22caeb650fe4672f129
- https://git.kernel.org/stable/c/affc18fdc694190ca7575b9a86632a73b9fe043d
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-613116.html
- https://cert-portal.siemens.com/productcert/html/ssa-355557.html