CVE-2024-26817
MEDIUMLinux Kernel < 4.19.312 - Integer Overflow
Title source: ruleDescription
In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid integer overflow This uses calloc instead of doing the multiplication which might overflow.
Exploits (1)
References (11)
Scores
CVSS v3
5.5
EPSS
0.0015
EPSS Percentile
34.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-190
Status
published
Products (10)
debian/debian_linux
10.0
linux/Kernel
3.19.0 - 4.19.312linux
linux/Kernel
4.20.0 - 5.4.274linux
linux/Kernel
5.11.0 - 5.15.155linux
linux/Kernel
5.16.0 - 6.1.86linux
linux/Kernel
5.5.0 - 5.10.215linux
linux/Kernel
6.2.0 - 6.6.27linux
linux/Kernel
6.7.0 - 6.8.6linux
linux/linux_kernel
6.9 rc1 (3 CPE variants)
linux/linux_kernel
< 4.19.312
Published
Apr 13, 2024
Tracked Since
Feb 18, 2026