CVE-2024-53228

In the Linux kernel, the following vulnerability has been resolved: riscv: kvm: Fix out-of-bounds array access In kvm_riscv_vcpu_sbi_init() the entry->ext_idx can contain an out-of-bound index. This is used as a special marker for the base extensions, that cannot be disabled. However, when traversing the extensions, that special marker is not checked prior indexing the array. Add an out-of-bounds check to the function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

16 Jan 2025, 16:46

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/332fa4a802b16ccb727199da685294f85f9880cb - () https://git.kernel.org/stable/c/332fa4a802b16ccb727199da685294f85f9880cb - Patch
References () https://git.kernel.org/stable/c/3c49e1084a5df99807fc43dd318c491e6cbaa168 - () https://git.kernel.org/stable/c/3c49e1084a5df99807fc43dd318c491e6cbaa168 - Patch
References () https://git.kernel.org/stable/c/b1af648f0d610665c956ea4604d9f797e5c7e991 - () https://git.kernel.org/stable/c/b1af648f0d610665c956ea4604d9f797e5c7e991 - Patch
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: riscv: kvm: Fix out-of-bounds array access En kvm_riscv_vcpu_sbi_init(), entry->ext_idx puede contener un índice fuera de los límites. Esto se utiliza como un marcador especial para las extensiones base, que no se pueden deshabilitar. Sin embargo, al recorrer las extensiones, ese marcador especial no se verifica antes de indexar la matriz. Agregue una verificación fuera de los límites a la función.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-129
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

27 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-27 14:15

Updated : 2025-01-16 16:46


NVD link : CVE-2024-53228

Mitre link : CVE-2024-53228

CVE.ORG link : CVE-2024-53228


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-129

Improper Validation of Array Index