We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-50259

netdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write()



Description

In the Linux kernel, the following vulnerability has been resolved: netdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write() This was found by a static analyzer. We should not forget the trailing zero after copy_from_user() if we will further do some string operations, sscanf() in this case. Adding a trailing zero will ensure that the function performs properly.

Reserved 2024-10-21 | Published 2024-11-09 | Updated 2024-11-19 | Assigner Linux

Product status

Default status
unaffected

c6385c0b67c5 before c2150f666c6f
affected

c6385c0b67c5 before bcba86e03b3a
affected

c6385c0b67c5 before 6a604877160f
affected

c6385c0b67c5 before 27bd7a742e17
affected

c6385c0b67c5 before 4ce1f56a1eac
affected

Default status
affected

5.13
affected

Any version before 5.13
unaffected

5.15.171
unaffected

6.1.116
unaffected

6.6.60
unaffected

6.11.7
unaffected

6.12
unaffected

References

git.kernel.org/...c/c2150f666c6fc301d5d1643ed0f92251f1a0ff0d

git.kernel.org/...c/bcba86e03b3aac361ea671672cf48eed11f9011c

git.kernel.org/...c/6a604877160fe5ab2e1985d5ce1ba6a61abe0693

git.kernel.org/...c/27bd7a742e171362c9eb52ad5d1d71d3321f949f

git.kernel.org/...c/4ce1f56a1eaced2523329bef800d004e30f2f76c

cve.org (CVE-2024-50259)

nvd.nist.gov (CVE-2024-50259)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-50259

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.