CVE-2024-53110: vp_vdpa: fix id_table array not null terminated error

0.0 CVSS

Description

In the Linux kernel, the following vulnerability has been resolved:

vp_vdpa: fix id_table array not null terminated error

Allocate one extra virtio_device_id as null terminator, otherwise
vdpa_mgmtdev_get_classes() may iterate multiple times and visit
undefined memory.

Classification

CVE ID: CVE-2024-53110

CVSS Base Severity: LOW

CVSS Base Score: 0.0

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 5.06% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://git.kernel.org/stable/c/870d68fe17b5d9032049dcad98b5781a344a8657
https://git.kernel.org/stable/c/c4d64534d4b1c47d2f1ce427497f971ad4735aae
https://git.kernel.org/stable/c/0a886489d274596ad1a80789d3a773503210a615
https://git.kernel.org/stable/c/4e39ecadf1d2a08187139619f1f314b64ba7d947

Timeline