CVE-2024-41028

Updated on 29 Jul 2024

Severity

7.8 High severity

Details

CVSS score
7.8

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: toshiba_acpi: Fix array out-of-bounds access

In order to use toshiba_dmi_quirks[] together with the standard DMI matching functions, it must be terminated by a empty entry.

Since this entry is missing, an array out-of-bounds access occurs every time the quirk list is processed.

Fix this by adding the terminating empty entry.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 12 Will Not Fix
Ubuntu 24.04 Planned