CVE-2024-50259

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-50259
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50259.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-50259
Downstream
Related
Published
2024-11-09T10:15:12.251Z
Modified
2025-11-28T02:35:34.720078Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
netdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write()
Details

In the Linux kernel, the following vulnerability has been resolved:

netdevsim: Add trailing zero to terminate the string in nsimnexthopbucketactivitywrite()

This was found by a static analyzer. We should not forget the trailing zero after copyfromuser() if we will further do some string operations, sscanf() in this case. Adding a trailing zero will ensure that the function performs properly.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50259.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c6385c0b67c527b298111775bc89a7407ba1581e
Fixed
c2150f666c6fc301d5d1643ed0f92251f1a0ff0d
Fixed
bcba86e03b3aac361ea671672cf48eed11f9011c
Fixed
6a604877160fe5ab2e1985d5ce1ba6a61abe0693
Fixed
27bd7a742e171362c9eb52ad5d1d71d3321f949f
Fixed
4ce1f56a1eaced2523329bef800d004e30f2f76c

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
5.15.171
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.116
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.60
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.11.7