CVE-2024-26967: clk: qcom: camcc-sc8280xp: fix terminating of frequency table arrays
In the Linux kernel, the following vulnerability has been resolved:
clk: qcom: camcc-sc8280xp: fix terminating of frequency table arrays
The frequency table arrays are supposed to be terminated with an empty element. Add such entry to the end of the arrays where it is missing in order to avoid possible out-of-bound access when the table is traversed by functions like qcomfindfreq() or qcomfindfreqfloor().
Only compile tested.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26967?
CVE-2024-26967 has been rated as a low severity vulnerability in the Linux kernel.
How do I fix CVE-2024-26967?
To fix CVE-2024-26967, update to the latest kernel version provided by your distribution that includes the fix.
Which Linux kernel versions are affected by CVE-2024-26967?
CVE-2024-26967 affects Linux kernel versions from 6.0.0 up to 6.8.3.
Is there a patch available for CVE-2024-26967?
Yes, a patch for CVE-2024-26967 has been implemented in the stable releases of the Linux kernel.
What systems are vulnerable to CVE-2024-26967?
Systems running affected versions of the Linux kernel without the latest updates are vulnerable to CVE-2024-26967.