Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-38541— of: module: add buffer overflow check in of_modalias()

CVSS 7.8 · High EPSS 0.89% · P56

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinuxbc575064d688c8933a6ca51429bea9bc63628d3b< 46795440ef2b4ac919d09310a69a404c5bc90a88affected
bc575064d688c8933a6ca51429bea9bc63628d3b< 733e62786bdf1b2b9dbb09ba2246313306503414affected
bc575064d688c8933a6ca51429bea9bc63628d3b< c7f24b7d94549ff4623e8f41ea4d9f5319bd8ac8affected
bc575064d688c8933a6ca51429bea9bc63628d3b< 5d59fd637a8af42b211a92b2edb2474325b4d488affected
bc575064d688c8933a6ca51429bea9bc63628d3b< 0b0d5701a8bf02f8fee037e81aacf6746558bfd6affected
bc575064d688c8933a6ca51429bea9bc63628d3b< ee332023adfd5882808f2dabf037b32d6ce36f9eaffected
bc575064d688c8933a6ca51429bea9bc63628d3b< e45b69360a63165377b30db4a1dfddd89ca18e9aaffected
bc575064d688c8933a6ca51429bea9bc63628d3b< cf7385cb26ac4f0ee6c7385960525ad534323252affected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-38541

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
of: module: add buffer overflow check in of_modalias()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: of: module: add buffer overflow check in of_modalias() In of_modalias(), if the buffer happens to be too small even for the 1st snprintf() call, the len parameter will become negative and str parameter (if not NULL initially) will point beyond the buffer's end. Add the buffer overflow check after the 1st snprintf() call and fix such check after the strlen() call (accounting for the terminating NUL char).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于of module of_modalias() 中存在安全问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux bc575064d688c8933a6ca51429bea9bc63628d3b ~ 46795440ef2b4ac919d09310a69a404c5bc90a88 -
LinuxLinux 4.14 -

II. Public POCs for CVE-2024-38541

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-38541

登录查看更多情报信息。

Patches & Fixes for CVE-2024-38541 (1)

Other References for CVE-2024-38541 (4)

Same Patch Batch · Linux · 2024-06-19 · 122 CVEs total

CVE-2024-3855810.0 CRITICALnet: openvswitch: fix overwriting ct original tuple for ICMPv6
CVE-2021-475879.8 CRITICALnet: systemport: Add global locking for descriptor lifecycle
CVE-2024-385449.8 CRITICALRDMA/rxe: Fix seg fault in rxe_comp_queue_pkt
CVE-2024-385709.8 CRITICALgfs2: Fix potential glock use-after-free on unmount
CVE-2021-476118.1 HIGHmac80211: validate extended element ID is present
CVE-2024-385887.8 HIGHftrace: Fix possible use-after-free issue in ftrace_location()
CVE-2024-385727.8 HIGHwifi: ath12k: fix out-of-bound access of qmi_invoke_handler()
CVE-2024-386107.8 HIGHdrivers/virt/acrn: fix PFNMAP PTE checks in acrn_vm_ram_map()
CVE-2024-386057.8 HIGHALSA: core: Fix NULL module pointer assignment at card init
CVE-2024-385997.8 HIGHjffs2: prevent xattr node from overflowing the eraseblock
CVE-2024-385787.8 HIGHecryptfs: Fix buffer size for tag 66 packet
CVE-2024-385927.8 HIGHdrm/mediatek: Init `ddp_comp` with devm_kcalloc()
CVE-2024-385647.8 HIGHbpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE
CVE-2024-385837.8 HIGHnilfs2: fix use-after-free of timer for log writer thread
CVE-2024-385687.8 HIGHdrivers/perf: hisi: hns3: Fix out-of-bound access when valid event group
CVE-2024-385807.8 HIGHepoll: be better about file lifetimes
CVE-2024-385817.8 HIGHdrm/amdgpu/mes: fix use-after-free issue
CVE-2024-385697.8 HIGHdrivers/perf: hisi_pcie: Fix out-of-bound access when valid event group
CVE-2024-386147.8 HIGHopenrisc: traps: Don't send signals to kernel mode threads
CVE-2024-385877.8 HIGHspeakup: Fix sizeof() vs ARRAY_SIZE() bug

Showing top 20 of 122 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-38541

No comments yet


Leave a comment