github.com
https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-jjf3-7x72-pqm9 CVE-2024-11263
CRITICAL
arch: riscv: userspace: potential security risk when CONFIG_RISCV_GP=y
Record summary
CVE-2024-11263 has a selected CVSS score of 9.4 (critical).
Description
When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which is then used by the linker to relax accesses to global symbols.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 18, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | * to ≤ 3.7 | affected |
Default status: unknown | CVE List | Through 3.7 | affected |