CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-50289: media: av7110: fix a spectre vulnerability

Description

In the Linux kernel, the following vulnerability has been resolved:

media: av7110: fix a spectre vulnerability

As warned by smatch:
drivers/staging/media/av7110/av7110_ca.c:270 dvb_ca_ioctl() warn: potential spectre issue 'av7110->ci_slot' [w] (local cap)

There is a spectre-related vulnerability at the code. Fix it.

Classification

CVE ID: CVE-2024-50289

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 8.82% (scored less or equal to compared to others)

EPSS Date: 2025-06-02 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-50289
https://git.kernel.org/stable/c/f3927206c478bd249c225414f7a751752a30e7b9
https://git.kernel.org/stable/c/458ea1c0be991573ec436aa0afa23baacfae101a

Timeline