Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-50129— net: pse-pd: Fix out of bound for loop

AI Predicted 4.4 Difficulty: Moderate EPSS 0.21% · P12

Affected Version Matrix 6

VendorProductVersion RangeStatus
LinuxLinux9be9567a7c59b7314ea776f56945fe3fc28efe99< 50ea68146d82f34b3ad80d8290ef8222136dedd7affected
9be9567a7c59b7314ea776f56945fe3fc28efe99< f2767a41959e60763949c73ee180e40c686e807eaffected
6.10affected
< 6.10unaffected
6.11.6≤ 6.11.*unaffected
6.12≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-50129

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net: pse-pd: Fix out of bound for loop
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: pse-pd: Fix out of bound for loop Adjust the loop limit to prevent out-of-bounds access when iterating over PI structures. The loop should not reach the index pcdev->nr_lines since we allocate exactly pcdev->nr_lines number of PI structures. This fix ensures proper bounds are maintained during iterations.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于net模块中,pse-pd模块的循环越界问题,由于迭代PI结构时循环限制未正确调整,可能导致越界访问。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 9be9567a7c59b7314ea776f56945fe3fc28efe99 ~ 50ea68146d82f34b3ad80d8290ef8222136dedd7 -
LinuxLinux 6.10 -

II. Public POCs for CVE-2024-50129

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-50129

登录查看更多情报信息。

Patches & Fixes for CVE-2024-50129 (2)

Same Patch Batch · Linux · 2024-11-05 · 50 CVEs total

CVE-2024-501069.8 CRITICALnfsd: fix race between laundromat and free_stateid
CVE-2024-501138.8 HIGHfirewire: core: fix invalid port index for parent device
CVE-2024-501158.4 HIGHKVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory
CVE-2024-501258.0 HIGHBluetooth: SCO: Fix UAF on sco_sock_timeout
CVE-2024-501248.0 HIGHBluetooth: ISO: Fix UAF on iso_sock_timeout
CVE-2024-501327.8 HIGHtracing/probes: Fix MAX_TRACE_ARGS limit handling
CVE-2023-529207.8 HIGHbpf: support non-r10 register spill/fill to/from stack in precision tracking
CVE-2024-500917.8 HIGHdm vdo: don't refer to dedupe_context after releasing it
CVE-2024-501017.8 HIGHiommu/vt-d: Fix incorrect pci_for_each_dma_alias() for non-PCI devices
CVE-2024-501147.8 HIGHKVM: arm64: Unregister redistributor for failed vCPU creation
CVE-2024-501277.8 HIGHnet: sched: fix use-after-free in taprio_change()
CVE-2024-501267.8 HIGHnet: sched: use RCU read-side critical section in taprio_dump()
CVE-2024-501287.8 HIGHnet: wwan: fix global oob in wwan_rtnl_policy
CVE-2024-501307.8 HIGHnetfilter: bpf: must hold reference on net namespace
CVE-2024-500907.8 HIGHdrm/xe/oa: Fix overflow in oa batch buffer
CVE-2024-500947.5 HIGHsfc: Don't invoke xdp_do_flush() from netpoll.
CVE-2024-500957.5 HIGHRDMA/mad: Improve handling of timed out WRs of mad agent
CVE-2024-501317.3 HIGHtracing: Consider the NULL character when validating the event length
CVE-2024-500997.3 HIGHarm64: probes: Remove broken LDR (literal) uprobe support
CVE-2024-500967.3 HIGHnouveau/dmem: Fix vulnerability in migrate_to_ram upon copy error

Showing top 20 of 50 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-50129

No comments yet


Leave a comment