2024-05-01 08:03:29 +00:00
{
"id" : "CVE-2024-27008" ,
"sourceIdentifier" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"published" : "2024-05-01T06:15:19.240" ,
2025-03-16 03:03:50 +00:00
"lastModified" : "2025-03-04T16:43:49.613" ,
2025-03-09 03:03:50 +00:00
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-05-01 08:03:29 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: nv04: Fix out of bounds access\n\nWhen Output Resource (dcb->or) value is assigned in\nfabricate_dcb_output(), there may be out of bounds access to\ndac_users array in case dcb->or is zero because ffs(dcb->or) is\nused as index there.\nThe 'or' argument of fabricate_dcb_output() must be interpreted as a\nnumber of bit to set, not value.\n\nUtilize macros from 'enum nouveau_or' in calls instead of hardcoding.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE."
2024-05-03 04:03:33 +00:00
} ,
{
"lang" : "es" ,
"value" : "En el kernel de Linux, se resolvi\u00f3 la siguiente vulnerabilidad: drm: nv04: corregir el acceso fuera de los l\u00edmites Cuando se asigna el valor del recurso de salida (dcb->or) en fabricate_dcb_output(), puede haber acceso fuera de los l\u00edmites a la matriz dac_users en caso de que dcb->or es cero porque ffs(dcb->or) se usa como \u00edndice all\u00ed. El argumento 'o' de fabricate_dcb_output() debe interpretarse como un n\u00famero de bits a configurar, no como un valor. Utilice macros de 'enum nouveau_or' en las llamadas en lugar de codificarlas. Encontrado por el Centro de verificaci\u00f3n de Linux (linuxtesting.org) con SVACE."
2024-05-01 08:03:29 +00:00
}
] ,
2025-03-09 03:03:50 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" ,
"baseScore" : 7.8 ,
"baseSeverity" : "HIGH" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-125"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2.6.38" ,
"versionEndExcluding" : "5.15.157" ,
"matchCriteriaId" : "47DBCABD-161C-4FF7-B5A5-FA633CF75B8B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "5.16" ,
"versionEndExcluding" : "6.1.88" ,
"matchCriteriaId" : "B665F958-644E-434D-A78D-CCD1628D1774"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.2" ,
"versionEndExcluding" : "6.6.29" ,
"matchCriteriaId" : "0999E154-1E68-41FA-8DE3-9A735E382224"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.7" ,
"versionEndExcluding" : "6.8.8" ,
"matchCriteriaId" : "673B3328-389D-41A4-9617-669298635262"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "22BEDD49-2C6D-402D-9DBF-6646F6ECD10B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*" ,
"matchCriteriaId" : "DF73CB2A-DFFD-46FB-9BFE-AA394F27EA37"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*" ,
"matchCriteriaId" : "52048DDA-FC5A-4363-95A0-A6357B4D7F8C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*" ,
"matchCriteriaId" : "A06B2CCF-3F43-4FA9-8773-C83C3F5764B2"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
}
]
}
]
}
] ,
2024-05-01 08:03:29 +00:00
"references" : [
{
2024-05-03 08:03:28 +00:00
"url" : "https://git.kernel.org/stable/c/097c7918fcfa1dee233acfd1f3029f00c3bc8062" ,
2025-03-09 03:03:50 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-05-01 08:03:29 +00:00
} ,
{
2024-05-03 08:03:28 +00:00
"url" : "https://git.kernel.org/stable/c/26212da39ee14a52c76a202c6ae5153a84f579a5" ,
2025-03-09 03:03:50 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-05-01 08:03:29 +00:00
} ,
{
2024-05-03 08:03:28 +00:00
"url" : "https://git.kernel.org/stable/c/5050ae879a828d752b439e3827aac126709da6d1" ,
2025-03-09 03:03:50 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-05-01 08:03:29 +00:00
} ,
{
2024-05-03 08:03:28 +00:00
"url" : "https://git.kernel.org/stable/c/5fd4b090304e450aa0e7cc9cc2b4873285c6face" ,
2025-03-09 03:03:50 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-05-01 08:03:29 +00:00
} ,
{
2024-05-03 08:03:28 +00:00
"url" : "https://git.kernel.org/stable/c/6690cc2732e2a8d0eaca44dcbac032a4b0148042" ,
2025-03-09 03:03:50 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-05-03 04:03:33 +00:00
} ,
{
2024-05-03 08:03:28 +00:00
"url" : "https://git.kernel.org/stable/c/c2b97f26f081ceec3298151481687071075a25cb" ,
2025-03-09 03:03:50 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-05-03 04:03:33 +00:00
} ,
{
2024-05-03 08:03:28 +00:00
"url" : "https://git.kernel.org/stable/c/cf92bb778eda7830e79452c6917efa8474a30c1e" ,
2025-03-09 03:03:50 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-05-03 04:03:33 +00:00
} ,
{
2024-05-03 08:03:28 +00:00
"url" : "https://git.kernel.org/stable/c/df0991da7db846f7fa4ec6740350f743d3b69b04" ,
2025-03-09 03:03:50 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/097c7918fcfa1dee233acfd1f3029f00c3bc8062" ,
2025-03-09 03:03:50 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/26212da39ee14a52c76a202c6ae5153a84f579a5" ,
2025-03-09 03:03:50 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/5050ae879a828d752b439e3827aac126709da6d1" ,
2025-03-09 03:03:50 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/5fd4b090304e450aa0e7cc9cc2b4873285c6face" ,
2025-03-09 03:03:50 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/6690cc2732e2a8d0eaca44dcbac032a4b0148042" ,
2025-03-09 03:03:50 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/c2b97f26f081ceec3298151481687071075a25cb" ,
2025-03-09 03:03:50 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/cf92bb778eda7830e79452c6917efa8474a30c1e" ,
2025-03-09 03:03:50 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/df0991da7db846f7fa4ec6740350f743d3b69b04" ,
2025-03-09 03:03:50 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Mailing List"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html" ,
2025-03-09 03:03:50 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html" ,
2025-03-09 03:03:50 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List"
]
2024-05-01 08:03:29 +00:00
}
]
}