CVE-2024-41028

HIGH EPSS 21.6%
Published Jul 29, 20241y ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Jul 29, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: platform/x86: toshiba_acpi: Fix array out-of-bounds access In order to use toshiba_dmi_quirks[] together with the standard DMI matching functions, it must be terminated by a empty entry. Since this entry is missing, an array out-of-bounds access occurs every time the quirk list is processed. Fix this by adding the terminating empty entry.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
21.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-129

Affected Products 10

VendorProductVersionRange
linuxlinux_kernel*≥6.1  –  <6.1.100
linuxlinux_kernel*≥6.2  –  <6.6.41
linuxlinux_kernel*≥6.7  –  <6.9.10
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any

References 5

  • git.kernel.org https://git.kernel.org/stable/c/0d71da43d6b7916d36cf1953d793da80433c50bf
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/639868f1cb87b683cf830353bbee0c4078202313
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b6e02c6b0377d4339986e07aeb696c632cd392aa
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e030aa6c972641cb069086a8c7a0f747653e472a
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/0d71da43d6b7916d36cf1953d793da80433c50bf
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/639868f1cb87b683cf830353bbee0c4078202313
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b6e02c6b0377d4339986e07aeb696c632cd392aa
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e030aa6c972641cb069086a8c7a0f747653e472a
    Patch