VDB

DEBIAN-CVE-2024-38381

DEBIAN-CVE-2024-38381 PUBLISHED CVSS 7.099999904632568 HIGH

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_rx_work syzbot reported the following uninit-value access issue [1] nci_rx_work() parses received packet from ndev->rx_q. It should be validated header size, payload size and total packet size before processing the packet. If an invalid packet is detected, it should be silently discarded.

Risk Scores

CVSS 3.1
7.099999904632568
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Affected Products

VendorProductVersions
Debian:13linux0, 0
Debian:11linux5.10.136-1, 5.10.70-1~bpo10+1, 5.10.84-1
Debian:12linux6.1.37-1, 6.1.38-1, 6.1.38-2
Debian:14linux0, 0

Timeline

  • Jun 21, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›