Fiche vulnérabilité
CVE-2024-36978 : faille élevée linux linux kernel (CVSS 7.8)
Description
In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in multiq_tune() q->bands will be assigned to qopt->bands to execute subsequent code logic after kmalloc. So the old q->bands should not be used in kmalloc. Otherwise, an out-of-bounds write will occur.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 19 juin 2024
- Dernière mise à jour
- 4 août 2026
Produits concernés
- linux linux kernel
Références
- Fiche CVE-2024-36978 sur le NVD (NIST)
- git.kernel.org/stable/c/0f208fad86631e005754606c3ec80c0d44a11…
- git.kernel.org/stable/c/52b1aa07cda6a199cd6754d3798c7759023bc…
- git.kernel.org/stable/c/54c2c171c11a798fe887b3ff72922aa9d1411…
- git.kernel.org/stable/c/598572c64287aee0b75bbba4e288149687886…
- git.kernel.org/stable/c/affc18fdc694190ca7575b9a86632a73b9fe0…
- git.kernel.org/stable/c/d5d9d241786f49ae7cbc08e7fc95a115e9d80…
- git.kernel.org/stable/c/d6fb5110e8722bc00748f22caeb650fe4672f…
- lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- cert-portal.siemens.com/productcert/html/ssa-265688.html
- cert-portal.siemens.com/productcert/html/ssa-355557.html
- cert-portal.siemens.com/productcert/html/ssa-613116.html