bugzilla.openanolis.cn
https://bugzilla.openanolis.cn/show_bug.cgi?id=8150 CVE-2024-24861
LOW
Race condition vulnerability in Linux kernel media/xc4000 xc4000_get_frequency()
Record summary
CVE-2024-24861 has a selected CVSS score of 3.3 (low).
Description
A race condition was found in the Linux kernel's media/xc4000 device driver in xc4000 xc4000_get_frequency() function. This can result in return value overflow issue, possibly leading to malfunction or denial of service issue.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 22, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | v3.1-rc1 to < v6.8-rc1 | affected |
References
4lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-24861