CVE-2024-35924

Source
https://cve.org/CVERecord?id=CVE-2024-35924
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35924.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-35924
Downstream
Related
Published
2024-05-19T10:10:35.044Z
Modified
2026-03-13T07:55:25.081352Z
Summary
usb: typec: ucsi: Limit read size on v1.2
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: ucsi: Limit read size on v1.2

Between UCSI 1.2 and UCSI 2.0, the size of the MESSAGE_IN region was increased from 16 to 256. In order to avoid overflowing reads for older systems, add a mechanism to use the read UCSI version to truncate read sizes on UCSI v1.2.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35924.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bdc62f2bae8fb0e8e99574de5232f0a3c54a27df
Fixed
266f403ec47573046dee4bcebda82777ce702c40
Fixed
0defcaa09d3b21e8387829ee3a652c43fa91e13f
Fixed
b3db266fb031fba88c423d4bb8983a73a3db6527

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35924.json"