Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-50259— netdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write()

AI Predicted 5.3 Difficulty: Moderate EPSS 0.22% · P13

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinuxc6385c0b67c527b298111775bc89a7407ba1581e< c2150f666c6fc301d5d1643ed0f92251f1a0ff0daffected
c6385c0b67c527b298111775bc89a7407ba1581e< bcba86e03b3aac361ea671672cf48eed11f9011caffected
c6385c0b67c527b298111775bc89a7407ba1581e< 6a604877160fe5ab2e1985d5ce1ba6a61abe0693affected
c6385c0b67c527b298111775bc89a7407ba1581e< 27bd7a742e171362c9eb52ad5d1d71d3321f949faffected
c6385c0b67c527b298111775bc89a7407ba1581e< 4ce1f56a1eaced2523329bef800d004e30f2f76caffected
5.13affected
< 5.13unaffected
5.15.171≤ 5.15.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-50259

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write() This was found by a static analyzer. We should not forget the trailing zero after copy_from_user() if we will further do some string operations, sscanf() in this case. Adding a trailing zero will ensure that the function performs properly.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于nsim_nexthop_bucket_activity_write函数存在字符串终止问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux c6385c0b67c527b298111775bc89a7407ba1581e ~ c2150f666c6fc301d5d1643ed0f92251f1a0ff0d -
LinuxLinux 5.13 -

II. Public POCs for CVE-2024-50259

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-50259

登录查看更多情报信息。

Patches & Fixes for CVE-2024-50259 (2)

Same Patch Batch · Linux · 2024-11-09 · 49 CVEs total

CVE-2024-502158.1 HIGHnvmet-auth: assign dh_key to NULL after kfree_sensitive
CVE-2024-502467.8 HIGHfs/ntfs3: Add rough attr alloc_size check
CVE-2024-502377.8 HIGHwifi: mac80211: do not pass a stopped vif to the driver in .get_txpower
CVE-2024-502357.8 HIGHwifi: cfg80211: clear wdev->cqm_config pointer on free
CVE-2024-502507.8 HIGHfsdax: dax_unshare_iter needs to copy entire blocks
CVE-2024-502307.8 HIGHnilfs2: fix kernel bug due to missing clearing of checked flag
CVE-2024-502537.8 HIGHbpf: Check the validity of nr_words in bpf_iter_bits_new()
CVE-2024-502257.8 HIGHbtrfs: fix error propagation of split bios
CVE-2024-502177.8 HIGHbtrfs: fix use-after-free of block device file in __btrfs_free_extra_devids()
CVE-2024-502627.8 HIGHbpf: Fix out-of-bounds write in trie_get_next_key()
CVE-2024-502617.8 HIGHmacsec: Fix use-after-free while sending the offloading packet
CVE-2024-502217.8 HIGHdrm/amd/pm: Vangogh: Fix kernel memory out of bounds write
CVE-2024-502567.5 HIGHnetfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6()
CVE-2024-502417.5 HIGHNFSD: Initialize struct nfsd4_copy earlier
CVE-2024-502477.3 HIGHfs/ntfs3: Check if more than chunk-size bytes are written
CVE-2024-502487.1 HIGHntfs3: Add bounds checking to mi_enum_attr()
CVE-2024-502227.0 HIGHiov_iter: fix copy_page_from_iter_atomic() if KMAP_LOCAL_FORCE_MAP
CVE-2024-502577.0 HIGHnetfilter: Fix use-after-free in get_info()
CVE-2024-50245fs/ntfs3: Fix possible deadlock in mi_read
CVE-2024-50243fs/ntfs3: Fix general protection fault in run_is_mapped_full

Showing top 20 of 49 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-50259

No comments yet


Leave a comment