CVE-2024-26971

MEDIUM

Linux Kernel 6.6-6.6.23, 6.7-6.7.11, 6.8-6.8.2 - Out-of-Bounds Read in Clock Frequency Table Traversal

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gcc-ipq5018: fix terminating of frequency table arrays The frequency table arrays are supposed to be terminated with an empty element. Add such entry to the end of the arrays where it is missing in order to avoid possible out-of-bound access when the table is traversed by functions like qcom_find_freq() or qcom_find_freq_floor().

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-129
Status published
Products (14)
linux/Kernel 6.6.0 - 6.6.24linux
linux/Kernel 6.7.0 - 6.7.12linux
linux/Kernel 6.8.0 - 6.8.3linux
Linux/Linux < 6.6
Linux/Linux 6.6
Linux/Linux 6.6.24 - 6.6.*
Linux/Linux 6.7.12 - 6.7.*
Linux/Linux 6.8.3 - 6.8.*
Linux/Linux 6.9
Linux/Linux e3fdbef1bab8e372981c8cc4d8febbaa76c490b0 - 50c3acd460551cdf9d8ac6fe0c04f2de0e8e0872
... and 4 more
Published May 01, 2024
Tracked Since Feb 18, 2026