CVE-2024-53106

Source
https://cve.org/CVERecord?id=CVE-2024-53106
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53106.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-53106
Downstream
Related
Published
2024-12-02T13:44:39.117Z
Modified
2026-05-28T03:55:17.302394440Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ima: fix buffer overrun in ima_eventdigest_init_common
Details

In the Linux kernel, the following vulnerability has been resolved:

ima: fix buffer overrun in imaeventdigestinit_common

Function imaeventdigestinit() calls imaeventdigestinitcommon() with HASHALGO__LAST which is then used to access the array hashdigestsize[] leading to buffer overrun. Have a conditional statement to handle this.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/53xxx/CVE-2024-53106.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9fab303a2cb3d323ca3a32a8b4ab60b451141901
Fixed
e01aae58e818503f2ffcd34c6f7dc6f90af1057e
Fixed
8a84765c62cc0469864e2faee43aae253ad16082
Fixed
1ecf0df5205cfb0907eb7984b8671257965a5232
Fixed
923168a0631bc42fffd55087b337b1b6c54dcff5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53106.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.1.119
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.63
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.11.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53106.json"