In the Linux kernel, the following vulnerability has been resolved:
regmap: maple: Fix cache corruption in regcache_maple_drop()
When keeping the upper end of a cache block entry, the entry[] array
must be indexed by the offset from the base register of the block,
i.e. max - mas.index.
The code was indexing entry[] by only the register address, leading
to an out-of-bounds access that copied some part of the kernel
memory over the cache contents.
This bug was not detected by the regmap KUnit test because it only
tests with a block of registers starting at 0, so mas.index == 0.
References
Configurations
Configuration 1 (hide)
|
History
18 Sep 2025, 15:54
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
| First Time |
Linux
Linux linux Kernel |
|
| References | () https://git.kernel.org/stable/c/00bb549d7d63a21532e76e4a334d7807a54d9f31 - Patch | |
| References | () https://git.kernel.org/stable/c/3af6c5ac72dc5b721058132a0a1d7779e443175e - Patch | |
| References | () https://git.kernel.org/stable/c/51c4440b9d3fd7c8234e6de9170a487c03506e53 - Patch | |
| CWE | CWE-125 |
Information
Published : 2024-05-30 15:15
Updated : 2025-09-18 15:54
NVD link : CVE-2024-36019
Mitre link : CVE-2024-36019
CVE.ORG link : CVE-2024-36019
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-125
Out-of-bounds Read
