CVE-2024-58069
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: rtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read The nvmem interface supports variable buffer sizes, while the regmap interface operates with fixed-size storage. If an nvmem client uses a buffer size less than 4 bytes, regmap_read will write out of bounds as it expects the buffer to point at an unsigned int. Fix this by using an intermediary unsigned int to hold the value.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.23%• Percentile: 14%
Techniques & Countermeasures
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- debian•linux
< 5.10.237-1 | < 6.1.129-1 | < 6.12.13-1 | < 6.12.13-1
- debian•linux-6.1
< 6.1.129-1~deb11u1
- ubuntu•linux
< 5.4.0-216.236 | < 5.15.0-140.150 | < 6.8.0-64.67
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 5.4.0-1146.156 | < 5.15.0-1084.91 | < 6.8.0-1032.34
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1084.91~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1146.156~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
all
- ubuntu•linux-aws-6.8
< 6.8.0-1032.34~22.04.1
- ubuntu•linux-aws-fips
< 5.4.0-1146.156+fips1 | all | < 5.15.0-1084.91+fips1
- ubuntu•linux-azure
all | < 5.4.0-1151.158 | < 5.15.0-1089.98 | < 6.8.0-1034.39
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1089.98~20.04.1
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1151.158~18.04.1
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.11
< 6.11.0-1015.15~24.04.1
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
all
- ubuntu•linux-azure-6.8
< 6.8.0-1034.39~22.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fips
< 5.4.0-1151.158+fips1 | all | < 5.15.0-1089.98+fips1
- ubuntu•linux-azure-nvidia
< 6.8.0-1022.23
- ubuntu•linux-bluefield
all | < 5.4.0-1105.112 | < 5.15.0-1066.68
- ubuntu•linux-fips
< 5.4.0-1120.130 | all | < 5.15.0-140.150+fips1 | < 6.8.0-78.78+fips1
- ubuntu•linux-gcp
all | < 5.4.0-1149.158 | < 5.15.0-1083.92 | < 6.8.0-1033.35
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1083.92~20.04.1
- ubuntu•linux-gcp-5.19
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1149.158~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-6.11
< 6.11.0-1015.15~24.04.1
- ubuntu•linux-gcp-6.2
all
- ubuntu•linux-gcp-6.5
all
- ubuntu•linux-gcp-6.8
< 6.8.0-1033.35~22.04.1
- ubuntu•linux-gcp-fips
< 5.4.0-1149.158+fips1 | all | < 5.15.0-1083.92+fips1
Showing first 50 affected entries in server-rendered view.
References (56)
- https://git.kernel.org/stable/c/21cd59fcb9952eb7505da2bdfc1eb9c619df3ff4
- https://git.kernel.org/stable/c/6f2a8ca9a0a38589f52a7f0fb9425b9ba987ae7c
- https://git.kernel.org/stable/c/e5536677da803ed54a29a446515c28dce7d3d574
- https://git.kernel.org/stable/c/c72b7a474d3f445bf0c5bcf8ffed332c78eb28a1
- https://git.kernel.org/stable/c/9adefa7b9559d0f21034a5d5ec1b55840c9348b9
- https://git.kernel.org/stable/c/e5e06455760f2995b16a176033909347929d1128
- https://git.kernel.org/stable/c/517aedb365f2c94e2d7e0b908ac7127df76203a1
- https://git.kernel.org/stable/c/3ab8c5ed4f84fa20cd16794fe8dc31f633fbc70c
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
- https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html
- https://ubuntu.com/security/CVE-2024-58069
- https://www.cve.org/CVERecord?id=CVE-2024-58069
- https://git.kernel.org/linus/3ab8c5ed4f84fa20cd16794fe8dc31f633fbc70c
- https://ubuntu.com/security/notices/USN-7510-1
- https://ubuntu.com/security/notices/USN-7510-2
- https://ubuntu.com/security/notices/USN-7511-1
- https://ubuntu.com/security/notices/USN-7511-2
- https://ubuntu.com/security/notices/USN-7512-1
- https://ubuntu.com/security/notices/USN-7516-1
- https://ubuntu.com/security/notices/USN-7516-2
- https://ubuntu.com/security/notices/USN-7517-1
- https://ubuntu.com/security/notices/USN-7518-1
- https://ubuntu.com/security/notices/USN-7521-1
- https://ubuntu.com/security/notices/USN-7510-3
- https://ubuntu.com/security/notices/USN-7510-4
- https://ubuntu.com/security/notices/USN-7510-5
- https://ubuntu.com/security/notices/USN-7511-3
- https://ubuntu.com/security/notices/USN-7516-3
- https://ubuntu.com/security/notices/USN-7516-4
- https://ubuntu.com/security/notices/USN-7517-2
- https://ubuntu.com/security/notices/USN-7521-2
- https://ubuntu.com/security/notices/USN-7516-5
- https://ubuntu.com/security/notices/USN-7516-6
- https://ubuntu.com/security/notices/USN-7517-3
- https://ubuntu.com/security/notices/USN-7510-6
- https://ubuntu.com/security/notices/USN-7521-3
- https://ubuntu.com/security/notices/USN-7510-7
- https://ubuntu.com/security/notices/USN-7539-1
- https://ubuntu.com/security/notices/USN-7540-1
- https://ubuntu.com/security/notices/USN-7516-7
- https://ubuntu.com/security/notices/USN-7516-8
- https://ubuntu.com/security/notices/USN-7510-8
- https://ubuntu.com/security/notices/USN-7516-9
- https://ubuntu.com/security/notices/USN-7593-1
- https://ubuntu.com/security/notices/USN-7602-1
- https://ubuntu.com/security/notices/USN-7640-1
- https://ubuntu.com/security/notices/USN-7651-1
- https://ubuntu.com/security/notices/USN-7652-1
- https://ubuntu.com/security/notices/USN-7653-1
- https://ubuntu.com/security/notices/USN-7651-2
- https://ubuntu.com/security/notices/USN-7651-3
- https://ubuntu.com/security/notices/USN-7651-4
- https://ubuntu.com/security/notices/USN-7651-5
- https://ubuntu.com/security/notices/USN-7651-6
- https://ubuntu.com/security/notices/USN-7737-1
- https://security-tracker.debian.org/tracker/CVE-2024-58069