CVE-2024-57792

HIGH

Linux Kernel 5.10-6.12.7 Memory Corruption via gpio-charger Current Limit Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: power: supply: gpio-charger: Fix set charge current limits Fix set charge current limits for devices which allow to set the lowest charge current limit to be greater zero. If requested charge current limit is below lowest limit, the index equals current_limit_map_size which leads to accessing memory beyond allocated memory.

Scores

CVSS v3 7.8
EPSS 0.0025
EPSS Percentile 16.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (21)
linux/Kernel 5.10.0 - 5.10.233linux
linux/Kernel 5.11.0 - 5.15.176linux
linux/Kernel 5.16.0 - 6.1.123linux
linux/Kernel 6.2.0 - 6.6.69linux
linux/Kernel 6.7.0 - 6.12.8linux
Linux/Linux < 5.10
Linux/Linux 5.10
Linux/Linux 5.10.233 - 5.10.*
Linux/Linux 5.15.176 - 5.15.*
Linux/Linux 6.1.123 - 6.1.*
... and 11 more
Published Jan 11, 2025
Tracked Since Feb 18, 2026