CVE-2024-26966: clk: qcom: mmcc-apq8084: fix terminating of frequency table arrays

Description

In the Linux kernel, the following vulnerability has been resolved:

clk: qcom: mmcc-apq8084: fix terminating of frequency table arrays

The frequency table arrays are supposed to be terminated with an
empty element. Add such entry to the end of the arrays where it
is missing in order to avoid possible out-of-bound access when
the table is traversed by functions like qcom_find_freq() or
qcom_find_freq_floor().

Only compile tested.

Classification

CVE ID: CVE-2024-26966

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 5.08% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://git.kernel.org/stable/c/5533686e99b04994d7c4877dc0e4282adc9444a2
https://git.kernel.org/stable/c/b2dfb216f32627c2f6a8041f2d9d56d102ab87c0
https://git.kernel.org/stable/c/a09aecb6cb482de88301c43bf00a6c8726c4d34f
https://git.kernel.org/stable/c/3aedcf3755c74dafc187eb76acb04e3e6348b1a9
https://git.kernel.org/stable/c/185de0b7cdeaad8b89ebd4c8a258ff2f21adba99
https://git.kernel.org/stable/c/9b4c4546dd61950e80ffdca1bf6925f42b665b03
https://git.kernel.org/stable/c/7e5432401536117c316d7f3b21d46b64c1514f38
https://git.kernel.org/stable/c/5638330150db2cc30b53eed04e481062faa3ece8
https://git.kernel.org/stable/c/a903cfd38d8dee7e754fb89fd1bebed99e28003d

Timeline