CVE-2024-50134

Updated: 2025-02-27 13:59:30.928893

Description:

In the Linux kernel, the following vulnerability has been resolved: drm/vboxvideo: Replace fake VLA at end of vbva_mouse_pointer_shape with real VLA Replace the fake VLA at end of the vbva_mouse_pointer_shape shape with a real VLA to fix a "memcpy: detected field-spanning write error" warning: [ 13.319813] memcpy: detected field-spanning write (size 16896) of single field "p->data" at drivers/gpu/drm/vboxvideo/hgsmi_base.c:154 (size 4) [ 13.319841] WARNING: CPU: 0 PID: 1105 at drivers/gpu/drm/vboxvideo/hgsmi_base.c:154 hgsmi_update_pointer_shape+0x192/0x1c0 [vboxvideo] [ 13.320038] Call Trace: [ 13.320173] hgsmi_update_pointer_shape [vboxvideo] [ 13.320184] vbox_cursor_atomic_update [vboxvideo] Note as mentioned in the added comment it seems the original length calculation for the allocated and send hgsmi buffer is 4 bytes too large. Changing this is not the goal of this patch, so this behavior is kept.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-03-03 21:58:01
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-03-03 21:58:01
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-03-03 21:58:00
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-03-03 21:58:00
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-03-03 21:58:00
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-03-03 21:58:00
CloudLinux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-03-03 21:58:01
CloudLinux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-03-02 21:45:56
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-03-03 21:58:00
Oracle Linux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-03-03 21:58:00
Total: 14