CVE-2024-42086

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-42086
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-42086.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-42086
Downstream
Related
Published
2024-07-29T16:26:27.075Z
Modified
2025-11-28T02:33:54.509088Z
Summary
iio: chemical: bme680: Fix overflows in compensate() functions
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: chemical: bme680: Fix overflows in compensate() functions

There are cases in the compensate functions of the driver that there could be overflows of variables due to bit shifting ops. These implications were initially discussed here [1] and they were mentioned in log message of Commit 1b3bd8592780 ("iio: chemical: Add support for Bosch BME680 sensor").

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/42xxx/CVE-2024-42086.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1b3bd8592780c87c5eddabbe98666b086bbaee36
Fixed
6fa31bbe2ea8665ee970258eb8320cbf231dbe9e
Fixed
b0af334616ed425024bf220adda0f004806b5feb
Fixed
c326551e99f5416986074ce78bef94f6a404b517
Fixed
7a13d1357658d3a3c1cd7b3b9543c805a6e5e6e9
Fixed
ba1bb3e2a38a7fef1c1818dd4f2d9abbfdde553a
Fixed
b5967393d50e3c6e632efda3ea3fdde14c1bfd0e
Fixed
3add41bbda92938e9a528d74659dfc552796be4e
Fixed
fdd478c3ae98c3f13628e110dce9b6cfb0d9b3c8

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.19.0
Fixed
4.19.317
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.279
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.221
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.162
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.97
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.37
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.9.8