Resolved vulnerability in Linux kernel's posix-clock
CVE-2024-50195

7.1HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
8 November 2024

What is CVE-2024-50195?

A vulnerability in the Linux kernel affects the precision time protocol (PTP) clock handling. It involves an improper validation of the 'timespec64' structure, which can lead to unsafe assumptions in driver implementations. Specific drivers may rely on time values without proper range checks, creating potential instability. This flaw requires validating both the 'tv_sec' and 'tv_nsec' values to ensure they reside within acceptable limits, preventing erroneous time settings in dynamic clocks.

Affected Version(s)

Linux 0606f422b453f76c31ab2b1bd52943ff06a2dcf2 < 29f085345cde24566efb751f39e5d367c381c584

Linux 0606f422b453f76c31ab2b1bd52943ff06a2dcf2

Linux 0606f422b453f76c31ab2b1bd52943ff06a2dcf2 < 673a1c5a2998acbd429d6286e6cad10f17f4f073

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.