CVE-2024-45008

In the Linux kernel, the following vulnerability has been resolved: Input: MT - limit max slots syzbot is reporting too large allocation at input_mt_init_slots(), for num_slots is supplied from userspace using ioctl(UI_DEV_CREATE). Since nobody knows possible max slots, this patch chose 1024.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.11:rc1:*:*:*:*:*:*

History

09 Oct 2025, 18:10

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.11:rc1:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/05dd9aabd04f9b5eb04dab9bb83d8c3e982d7549 - () https://git.kernel.org/stable/c/05dd9aabd04f9b5eb04dab9bb83d8c3e982d7549 - Patch
References () https://git.kernel.org/stable/c/2829c80614890624456337e47320289112785f3e - () https://git.kernel.org/stable/c/2829c80614890624456337e47320289112785f3e - Patch
References () https://git.kernel.org/stable/c/87f610a1a7fbdb1f2e3d90b54c955bd3b8a0c322 - () https://git.kernel.org/stable/c/87f610a1a7fbdb1f2e3d90b54c955bd3b8a0c322 - Patch
References () https://git.kernel.org/stable/c/8f04edd554d191834e9e1349ef030318ea6b11ba - () https://git.kernel.org/stable/c/8f04edd554d191834e9e1349ef030318ea6b11ba - Patch
References () https://git.kernel.org/stable/c/94736334b8a25e4fae8daa6934e54a31f099be43 - () https://git.kernel.org/stable/c/94736334b8a25e4fae8daa6934e54a31f099be43 - Patch
References () https://git.kernel.org/stable/c/95f73d01f547dfc67fda3022c51e377a0454b505 - () https://git.kernel.org/stable/c/95f73d01f547dfc67fda3022c51e377a0454b505 - Patch
References () https://git.kernel.org/stable/c/99d3bf5f7377d42f8be60a6b9cb60fb0be34dceb - () https://git.kernel.org/stable/c/99d3bf5f7377d42f8be60a6b9cb60fb0be34dceb - Patch
References () https://git.kernel.org/stable/c/cd19f1799c32ba7b874474b1b968815ce5364f73 - () https://git.kernel.org/stable/c/cd19f1799c32ba7b874474b1b968815ce5364f73 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

05 Sep 2024, 12:53

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: Entrada: MT - límite de ranuras máximas syzbot informa una asignación demasiado grande en input_mt_init_slots(), ya que num_slots se suministra desde el espacio de usuario mediante ioctl(UI_DEV_CREATE). Como nadie conoce la cantidad máxima de ranuras posibles, este parche eligió 1024.

04 Sep 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-04 20:15

Updated : 2025-10-09 18:10


NVD link : CVE-2024-45008

Mitre link : CVE-2024-45008

CVE.ORG link : CVE-2024-45008


JSON object : View

Products Affected

linux

  • linux_kernel