CVE-2024-44993
Linux
CVE-2024-44993 is a vulnerability in the Linux kernel, specifically an out-of-bounds read within the v3d_csd_job_run()
function in the V3D graphics driver. This flaw can occur when the system attempts to access memory beyond the allocated boundary of a configuration register array. The SVRS score of 65 indicates a moderate level of risk, suggesting prompt attention, though not necessarily immediate action. An attacker could potentially exploit this flaw to cause a system crash or potentially leak sensitive information from kernel memory. The vulnerability stems from reading beyond the defined size of the UAPI configuration registers, which are defined as seven, while the code attempts to access the eighth. This out-of-bounds read can lead to unpredictable behavior and system instability, particularly on systems like the Raspberry Pi 5. While the CVSS score is 7.1 indicating high severity, the slightly lower SVRS suggests that real-world exploitability might be somewhat limited, but mitigation is still advisable to maintain system integrity.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.