In the Linux kernel, the following vulnerability has been resolved:
vdpa: solidrun: Fix UB bug with devres
In psnet_open_pf_bar() and snet_open_vf_bar() a string later passed to
pcim_iomap_regions() is placed on the stack. Neither
pcim_iomap_regions() nor the functions it calls copy that string.
Should the string later ever be used, this, consequently, causes
undefined behavior since the stack frame will by then have disappeared.
Fix the bug by allocating the strings on the heap through
devm_kasprintf().
References
Configurations
Configuration 1 (hide)
|
History
11 Dec 2024, 17:26
Type | Values Removed | Values Added |
---|---|---|
First Time |
Linux linux Kernel
Linux |
|
CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CWE | NVD-CWE-noinfo | |
References | () https://git.kernel.org/stable/c/0b364cf53b20204e92bac7c6ebd1ee7d3ec62931 - Patch | |
References | () https://git.kernel.org/stable/c/5bb287da2d2d5bb8f7376e223b02edb16998982e - Patch | |
References | () https://git.kernel.org/stable/c/d372dd09cfbf1324f54cbffd81fcaf6cdf3e608e - Patch | |
Summary |
|
04 Dec 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-04 15:15
Updated : 2024-12-11 17:26
NVD link : CVE-2024-53126
Mitre link : CVE-2024-53126
CVE.ORG link : CVE-2024-53126
JSON object : View
Products Affected
linux
- linux_kernel
CWE