CVE-2024-53106

Source
https://cve.org/CVERecord?id=CVE-2024-53106
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53106.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-53106
Downstream
Related
Published
2024-12-02T13:44:39Z
Modified
2026-08-12T03:30:31Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H CVSS Calculator
Summary
ima: fix buffer overrun in ima_eventdigest_init_common
Details

In the Linux kernel, the following vulnerability has been resolved:

ima: fix buffer overrun in ima_eventdigest_init_common

Function ima_eventdigest_init() calls ima_eventdigest_init_common() with HASH_ALGO__LAST which is then used to access the array hash_digest_size[] leading to buffer overrun. Have a conditional statement to handle this.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/53xxx/CVE-2024-53106.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9fab303a2cb3d323ca3a32a8b4ab60b451141901
Fixed
e01aae58e818503f2ffcd34c6f7dc6f90af1057e
Fixed
8a84765c62cc0469864e2faee43aae253ad16082
Fixed
1ecf0df5205cfb0907eb7984b8671257965a5232
Fixed
923168a0631bc42fffd55087b337b1b6c54dcff5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53106.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.1.119
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.63
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.11.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53106.json"