CVE-2024-36978

Updated: 2024-11-24 04:01:28.44345

Description:

In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in multiq_tune() q->bands will be assigned to qopt->bands to execute subsequent code logic after kmalloc. So the old q->bands should not be used in kmalloc. Otherwise, an out-of-bounds write will occur.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Released CLSA-2025:1743193221 2024-11-18 16:44:55
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2024-10-17 00:06:28
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2024-10-17 00:06:28
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1725872696 2024-09-09 05:27:40
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1725876080 2024-09-09 12:17:51
CentOS Stream 8 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1725871927 2024-09-09 05:27:39
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2024-10-17 00:06:28
CloudLinux 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2024-10-17 00:06:27
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Ignored 2024-07-25 05:17:33
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Not Vulnerable 2024-09-16 12:25:18
Total: 11