CVE-2024-42242

MEDIUM

Linux Kernel 6.9-6.9.9 - Denial of Service via Incorrect MMC Segment Size Validation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci: Fix max_seg_size for 64KiB PAGE_SIZE blk_queue_max_segment_size() ensured: if (max_size < PAGE_SIZE) max_size = PAGE_SIZE; whereas: blk_validate_limits() makes it an error: if (WARN_ON_ONCE(lim->max_segment_size < PAGE_SIZE)) return -EINVAL; The change from one to the other, exposed sdhci which was setting maximum segment size too low in some circumstances. Fix the maximum segment size when it is too low.

Scores

CVSS v3 5.5
EPSS 0.0018
EPSS Percentile 7.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (8)
linux/Kernel 6.9.0 - 6.9.10linux
Linux/Linux < 6.9
Linux/Linux 6.10
Linux/Linux 6.9
Linux/Linux 6.9.10 - 6.9.*
Linux/Linux 616f8766179277324393f7b77e07f14cb3503825 - 63d20a94f24fc1cbaf44d0e7c0e0a8077fde0aef
Linux/Linux 616f8766179277324393f7b77e07f14cb3503825 - bf78b1accef46efd9b624967cb74ae8d3c215a2b
linux/linux_kernel 6.9 - 6.9.10
Published Aug 07, 2024
Tracked Since Feb 18, 2026