CVE-2024-40994

Source
https://cve.org/CVERecord?id=CVE-2024-40994
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-40994.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-40994
Downstream
Related
Published
2024-07-12T12:37:37.124Z
Modified
2026-05-07T04:18:31.795266Z
Summary
ptp: fix integer overflow in max_vclocks_store
Details

In the Linux kernel, the following vulnerability has been resolved:

ptp: fix integer overflow in maxvclocksstore

On 32bit systems, the "4 * max" multiply can overflow. Use kcalloc() to do the allocation to prevent this.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/40xxx/CVE-2024-40994.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
44c494c8e30e35713c7d11ca3c5ab332cbfabacf
Fixed
4b03da87d0b7074c93d9662c6e1a8939f9b8b86e
Fixed
d50d62d5e6ee6aa03c00bddb91745d0b632d3b0f
Fixed
666e934d749e50a37f3796caaf843a605f115b6f
Fixed
e1fccfb4638ee6188377867f6015d0ce35764a8e
Fixed
81d23d2a24012e448f651e007fac2cfd20a45ce0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-40994.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
5.15.162
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.96
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.36
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.9.7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-40994.json"