CVE-2024-35924

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Limit read size on v1.2 Between UCSI 1.2 and UCSI 2.0, the size of the MESSAGE_IN region was increased from 16 to 256. In order to avoid overflowing reads for older systems, add a mechanism to use the read UCSI version to truncate read sizes on UCSI v1.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

24 Sep 2025, 18:47

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://git.kernel.org/stable/c/0defcaa09d3b21e8387829ee3a652c43fa91e13f - () https://git.kernel.org/stable/c/0defcaa09d3b21e8387829ee3a652c43fa91e13f - Patch
References () https://git.kernel.org/stable/c/266f403ec47573046dee4bcebda82777ce702c40 - () https://git.kernel.org/stable/c/266f403ec47573046dee4bcebda82777ce702c40 - Patch
References () https://git.kernel.org/stable/c/b3db266fb031fba88c423d4bb8983a73a3db6527 - () https://git.kernel.org/stable/c/b3db266fb031fba88c423d4bb8983a73a3db6527 - Patch

21 Nov 2024, 09:21

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux se ha resuelto la siguiente vulnerabilidad: usb: typec: ucsi: Limitar el tamaño de lectura en v1.2 Entre UCSI 1.2 y UCSI 2.0, el tamaño de la región MESSAGE_IN se incrementó de 16 a 256. Para evitar el desbordamiento lecturas para sistemas más antiguos, agregue un mecanismo para usar la versión de lectura UCSI para truncar los tamaños de lectura en UCSI v1.2.
References () https://git.kernel.org/stable/c/0defcaa09d3b21e8387829ee3a652c43fa91e13f - () https://git.kernel.org/stable/c/0defcaa09d3b21e8387829ee3a652c43fa91e13f -
References () https://git.kernel.org/stable/c/266f403ec47573046dee4bcebda82777ce702c40 - () https://git.kernel.org/stable/c/266f403ec47573046dee4bcebda82777ce702c40 -
References () https://git.kernel.org/stable/c/b3db266fb031fba88c423d4bb8983a73a3db6527 - () https://git.kernel.org/stable/c/b3db266fb031fba88c423d4bb8983a73a3db6527 -

19 May 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-19 11:15

Updated : 2025-09-24 18:47


NVD link : CVE-2024-35924

Mitre link : CVE-2024-35924

CVE.ORG link : CVE-2024-35924


JSON object : View

Products Affected

linux

  • linux_kernel