CVE-2024-42238

MEDIUM

Linux Kernel 5.16-6.1.99, 6.2-6.6.40, 6.7-6.9.9 - Buffer Overflow in CS_DSP Firmware Block Header Processing

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Return error if block header overflows file Return an error from cs_dsp_power_up() if a block header is longer than the amount of data left in the file. The previous code in cs_dsp_load() and cs_dsp_load_coeff() would loop while there was enough data left in the file for a valid region. This protected against overrunning the end of the file data, but it didn't abort the file processing with an error.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-120
Status published
Products (14)
linux/Kernel 5.16.0 - 6.1.100linux
linux/Kernel 6.2.0 - 6.6.41linux
linux/Kernel 6.7.0 - 6.9.10linux
Linux/Linux < 5.16
Linux/Linux 5.16
Linux/Linux 6.1.100 - 6.1.*
Linux/Linux 6.10
Linux/Linux 6.6.41 - 6.6.*
Linux/Linux 6.9.10 - 6.9.*
Linux/Linux f6bc909e7673c30abcbdb329e7d0aa2e83c103d7 - 6eabd23383805725eff416c203688b7a390d4153
... and 4 more
Published Aug 07, 2024
Tracked Since Feb 18, 2026