CVE-2024-43877

HIGH

Linux Kernel 5.16-6.1.103, 6.2-6.6.44, 6.7-6.10.3 - Out-of-bounds Read in IVTV DMA Mapping

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: media: pci: ivtv: Add check for DMA map result In case DMA fails, 'dma->SG_length' is 0. This value is later used to access 'dma->SGarray[dma->SG_length - 1]', which will cause out of bounds access. Add check to return early on invalid value. Adjust warnings accordingly. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Scores

CVSS v3 7.1
EPSS 0.0022
EPSS Percentile 12.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (18)
linux/Kernel 5.16.0 - 6.1.103linux
linux/Kernel 6.2.0 - 6.6.44linux
linux/Kernel 6.7.0 - 6.10.3linux
Linux/Linux < 5.16
Linux/Linux 1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1 - 24062aa7407091dee3e45a8e8037df437e848718
Linux/Linux 1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1 - 3d8fd92939e21ff0d45100ab208f8124af79402a
Linux/Linux 1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1 - 629913d6d79508b166c66e07e4857e20233d85a9
Linux/Linux 1932dc2f4cf6ac23e48e5fcc24d21adbe35691d1 - c766065e8272085ea9c436414b7ddf1f12e7787b
Linux/Linux 1b00b7335000c0e107f774cc8ee4d5340f824f28
Linux/Linux 4551236b55e80b2c1720b10b77e9400118b2339e - 38f72c7e7c6b55614f9407555fd5ce9d019b0fa4
... and 8 more
Published Aug 21, 2024
Tracked Since Feb 18, 2026