CVE-2024-26965 (GCVE-0-2024-26965)
Vulnerability from cvelistv5
Published
2024-05-01 05:19
Modified
2026-08-05 11:28
Summary
In the Linux kernel, the following vulnerability has been resolved: clk: qcom: mmcc-msm8974: fix terminating of frequency table arrays The frequency table arrays are supposed to be terminated with an empty element. Add such entry to the end of the arrays where it is missing in order to avoid possible out-of-bound access when the table is traversed by functions like qcom_find_freq() or qcom_find_freq_floor(). Only compile tested.
Impacted products
Vendor Product Version
Linux Linux Version: d8b212014e69d6b6323773ce6898f224ef4ed0d6
Version: d8b212014e69d6b6323773ce6898f224ef4ed0d6
Version: d8b212014e69d6b6323773ce6898f224ef4ed0d6
Version: d8b212014e69d6b6323773ce6898f224ef4ed0d6
Version: d8b212014e69d6b6323773ce6898f224ef4ed0d6
Version: d8b212014e69d6b6323773ce6898f224ef4ed0d6
Version: d8b212014e69d6b6323773ce6898f224ef4ed0d6
Version: d8b212014e69d6b6323773ce6898f224ef4ed0d6
Version: d8b212014e69d6b6323773ce6898f224ef4ed0d6
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-26965",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-05-28T17:50:48.637005Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-04T17:49:04.278Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T00:21:05.666Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/99740c4791dc8019b0d758c5389ca6d1c0604d95"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/86bf75d9158f511db7530bc82a84b19a5134d089"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/3ff4a0f6a8f0ad4b4ee9e908bdfc3cacb7be4060"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/8f562f3b25177c2055b20fd8cf000496f6fa9194"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/537040c257ab4cd0673fbae048f3940c8ea2e589"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/7e9926fef71e514b4a8ea9d11d5a84d52b181362"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/ae99e199037c580b7350bfa3596f447a53bcf01f"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/ca2cf98d46748373e830a13d85d215d64a2d9bf2"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/e2c02a85bf53ae86d79b5fccf0a75ac0b78e0c96"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/clk/qcom/mmcc-msm8974.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "99740c4791dc8019b0d758c5389ca6d1c0604d95",
              "status": "affected",
              "version": "d8b212014e69d6b6323773ce6898f224ef4ed0d6",
              "versionType": "git"
            },
            {
              "lessThan": "86bf75d9158f511db7530bc82a84b19a5134d089",
              "status": "affected",
              "version": "d8b212014e69d6b6323773ce6898f224ef4ed0d6",
              "versionType": "git"
            },
            {
              "lessThan": "3ff4a0f6a8f0ad4b4ee9e908bdfc3cacb7be4060",
              "status": "affected",
              "version": "d8b212014e69d6b6323773ce6898f224ef4ed0d6",
              "versionType": "git"
            },
            {
              "lessThan": "8f562f3b25177c2055b20fd8cf000496f6fa9194",
              "status": "affected",
              "version": "d8b212014e69d6b6323773ce6898f224ef4ed0d6",
              "versionType": "git"
            },
            {
              "lessThan": "537040c257ab4cd0673fbae048f3940c8ea2e589",
              "status": "affected",
              "version": "d8b212014e69d6b6323773ce6898f224ef4ed0d6",
              "versionType": "git"
            },
            {
              "lessThan": "7e9926fef71e514b4a8ea9d11d5a84d52b181362",
              "status": "affected",
              "version": "d8b212014e69d6b6323773ce6898f224ef4ed0d6",
              "versionType": "git"
            },
            {
              "lessThan": "ae99e199037c580b7350bfa3596f447a53bcf01f",
              "status": "affected",
              "version": "d8b212014e69d6b6323773ce6898f224ef4ed0d6",
              "versionType": "git"
            },
            {
              "lessThan": "ca2cf98d46748373e830a13d85d215d64a2d9bf2",
              "status": "affected",
              "version": "d8b212014e69d6b6323773ce6898f224ef4ed0d6",
              "versionType": "git"
            },
            {
              "lessThan": "e2c02a85bf53ae86d79b5fccf0a75ac0b78e0c96",
              "status": "affected",
              "version": "d8b212014e69d6b6323773ce6898f224ef4ed0d6",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/clk/qcom/mmcc-msm8974.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.14"
            },
            {
              "lessThan": "3.14",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.312",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.274",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.215",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.154",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.84",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.24",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.12",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.9",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.312",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.274",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.215",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.154",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.84",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.24",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.12",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.3",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: qcom: mmcc-msm8974: fix terminating of frequency table arrays\n\nThe frequency table arrays are supposed to be terminated with an\nempty element. Add such entry to the end of the arrays where it\nis missing in order to avoid possible out-of-bound access when\nthe table is traversed by functions like qcom_find_freq() or\nqcom_find_freq_floor().\n\nOnly compile tested."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code is the Qualcomm MMCC clock controller driver, reached only through in-kernel clock-rate requests originating from local device interfaces (DRM/KMS on /dev/dri/card*, V4L2 on /dev/video*, OCMEM). There is no network-facing path to the frequency-table walk.\nAC:L - The out-of-bounds walk is fully deterministic \u2014 any rate request exceeding the table maximum runs off the end, with no race, no timing window, and no dependence on memory layout the attacker cannot influence. The adjacent .data contents are fixed at build and registration time, so the outcome is reproducible on every attempt.\nPR:L - An unprivileged local user with ordinary access to the display or camera/video device nodes (standard for the video/render groups on the Android and embedded MSM8974/MSM8226 devices this driver targets) can drive rate requests through mdss_axi_clk and the *_ocmemnoc branches, which carry CLK_SET_RATE_PARENT into the two unterminated tables. No root or capability is needed.\nUI:N - The clock-rate request is issued by the attacker\u0027s own ioctl/modeset activity on the display or video device; no victim action or separate user is involved.\nS:U - The out-of-bounds read, the leaked data, and the resulting misprogrammed clock all remain within the kernel\u0027s own security authority. No hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - The loop is an unbounded out-of-bounds read with no length check, walking adjacent .data that contains live kernel pointers (parent_map, freq_tbl, clkr.regmap, clkr.hw.core) in the neighbouring struct clk_rcg2. The OOB entry\u0027s freq is propagated to req-\u003erate and surfaces to userspace via clk_round_rate() and the clk_rate debugfs node, disclosing kernel .data and defeating KASLR.\nI:L - The out-of-bounds src, pre_div, m and n values are written into the RCG CFG/M/N/D hardware registers, reprogramming the MMSS AXI / OCMEM NoC bus clock with an unintended source and divider \u2014 a real modification of system state. The values are not attacker-controlled and there is no out-of-bounds write into kernel memory, so this falls short of a full integrity compromise.\nA:H - The global out-of-bounds read triggers a KASAN global-OOB report (fatal under panic_on_warn) and the unterminated walk can run past the end of the section, while programming a garbage source select and divider into the multimedia bus clock can hang the MMSS bus and lock up the SoC."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:28:40.872Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/99740c4791dc8019b0d758c5389ca6d1c0604d95"
        },
        {
          "url": "https://git.kernel.org/stable/c/86bf75d9158f511db7530bc82a84b19a5134d089"
        },
        {
          "url": "https://git.kernel.org/stable/c/3ff4a0f6a8f0ad4b4ee9e908bdfc3cacb7be4060"
        },
        {
          "url": "https://git.kernel.org/stable/c/8f562f3b25177c2055b20fd8cf000496f6fa9194"
        },
        {
          "url": "https://git.kernel.org/stable/c/537040c257ab4cd0673fbae048f3940c8ea2e589"
        },
        {
          "url": "https://git.kernel.org/stable/c/7e9926fef71e514b4a8ea9d11d5a84d52b181362"
        },
        {
          "url": "https://git.kernel.org/stable/c/ae99e199037c580b7350bfa3596f447a53bcf01f"
        },
        {
          "url": "https://git.kernel.org/stable/c/ca2cf98d46748373e830a13d85d215d64a2d9bf2"
        },
        {
          "url": "https://git.kernel.org/stable/c/e2c02a85bf53ae86d79b5fccf0a75ac0b78e0c96"
        }
      ],
      "title": "clk: qcom: mmcc-msm8974: fix terminating of frequency table arrays",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-26965",
    "datePublished": "2024-05-01T05:19:32.635Z",
    "dateReserved": "2024-02-19T14:20:24.201Z",
    "dateUpdated": "2026-08-05T11:28:40.872Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/99740c4791dc8019b0d758c5389ca6d1c0604d95\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/86bf75d9158f511db7530bc82a84b19a5134d089\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/3ff4a0f6a8f0ad4b4ee9e908bdfc3cacb7be4060\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/8f562f3b25177c2055b20fd8cf000496f6fa9194\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/537040c257ab4cd0673fbae048f3940c8ea2e589\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/7e9926fef71e514b4a8ea9d11d5a84d52b181362\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/ae99e199037c580b7350bfa3596f447a53bcf01f\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/ca2cf98d46748373e830a13d85d215d64a2d9bf2\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/e2c02a85bf53ae86d79b5fccf0a75ac0b78e0c96\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T00:21:05.666Z\"}}, {\"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-26965\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-05-28T17:50:48.637005Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-05-28T17:50:52.466Z\"}, \"title\": \"CISA ADP Vulnrichment\"}], \"cna\": {\"title\": \"clk: qcom: mmcc-msm8974: fix terminating of frequency table arrays\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.3, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerable code is the Qualcomm MMCC clock controller driver, reached only through in-kernel clock-rate requests originating from local device interfaces (DRM/KMS on /dev/dri/card*, V4L2 on /dev/video*, OCMEM). There is no network-facing path to the frequency-table walk.\\nAC:L - The out-of-bounds walk is fully deterministic \\u2014 any rate request exceeding the table maximum runs off the end, with no race, no timing window, and no dependence on memory layout the attacker cannot influence. The adjacent .data contents are fixed at build and registration time, so the outcome is reproducible on every attempt.\\nPR:L - An unprivileged local user with ordinary access to the display or camera/video device nodes (standard for the video/render groups on the Android and embedded MSM8974/MSM8226 devices this driver targets) can drive rate requests through mdss_axi_clk and the *_ocmemnoc branches, which carry CLK_SET_RATE_PARENT into the two unterminated tables. No root or capability is needed.\\nUI:N - The clock-rate request is issued by the attacker\u0027s own ioctl/modeset activity on the display or video device; no victim action or separate user is involved.\\nS:U - The out-of-bounds read, the leaked data, and the resulting misprogrammed clock all remain within the kernel\u0027s own security authority. No hypervisor, IOMMU, or sandbox boundary is crossed.\\nC:H - The loop is an unbounded out-of-bounds read with no length check, walking adjacent .data that contains live kernel pointers (parent_map, freq_tbl, clkr.regmap, clkr.hw.core) in the neighbouring struct clk_rcg2. The OOB entry\u0027s freq is propagated to req-\u003erate and surfaces to userspace via clk_round_rate() and the clk_rate debugfs node, disclosing kernel .data and defeating KASLR.\\nI:L - The out-of-bounds src, pre_div, m and n values are written into the RCG CFG/M/N/D hardware registers, reprogramming the MMSS AXI / OCMEM NoC bus clock with an unintended source and divider \\u2014 a real modification of system state. The values are not attacker-controlled and there is no out-of-bounds write into kernel memory, so this falls short of a full integrity compromise.\\nA:H - The global out-of-bounds read triggers a KASAN global-OOB report (fatal under panic_on_warn) and the unterminated walk can run past the end of the section, while programming a garbage source select and divider into the multimedia bus clock can hang the MMSS bus and lock up the SoC.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"d8b212014e69d6b6323773ce6898f224ef4ed0d6\", \"lessThan\": \"99740c4791dc8019b0d758c5389ca6d1c0604d95\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d8b212014e69d6b6323773ce6898f224ef4ed0d6\", \"lessThan\": \"86bf75d9158f511db7530bc82a84b19a5134d089\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d8b212014e69d6b6323773ce6898f224ef4ed0d6\", \"lessThan\": \"3ff4a0f6a8f0ad4b4ee9e908bdfc3cacb7be4060\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d8b212014e69d6b6323773ce6898f224ef4ed0d6\", \"lessThan\": \"8f562f3b25177c2055b20fd8cf000496f6fa9194\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d8b212014e69d6b6323773ce6898f224ef4ed0d6\", \"lessThan\": \"537040c257ab4cd0673fbae048f3940c8ea2e589\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d8b212014e69d6b6323773ce6898f224ef4ed0d6\", \"lessThan\": \"7e9926fef71e514b4a8ea9d11d5a84d52b181362\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d8b212014e69d6b6323773ce6898f224ef4ed0d6\", \"lessThan\": \"ae99e199037c580b7350bfa3596f447a53bcf01f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d8b212014e69d6b6323773ce6898f224ef4ed0d6\", \"lessThan\": \"ca2cf98d46748373e830a13d85d215d64a2d9bf2\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d8b212014e69d6b6323773ce6898f224ef4ed0d6\", \"lessThan\": \"e2c02a85bf53ae86d79b5fccf0a75ac0b78e0c96\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/clk/qcom/mmcc-msm8974.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"3.14\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"3.14\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"4.19.312\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"4.19.*\"}, {\"status\": \"unaffected\", \"version\": \"5.4.274\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.215\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.154\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.84\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.24\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.7.12\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.3\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/clk/qcom/mmcc-msm8974.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/99740c4791dc8019b0d758c5389ca6d1c0604d95\"}, {\"url\": \"https://git.kernel.org/stable/c/86bf75d9158f511db7530bc82a84b19a5134d089\"}, {\"url\": \"https://git.kernel.org/stable/c/3ff4a0f6a8f0ad4b4ee9e908bdfc3cacb7be4060\"}, {\"url\": \"https://git.kernel.org/stable/c/8f562f3b25177c2055b20fd8cf000496f6fa9194\"}, {\"url\": \"https://git.kernel.org/stable/c/537040c257ab4cd0673fbae048f3940c8ea2e589\"}, {\"url\": \"https://git.kernel.org/stable/c/7e9926fef71e514b4a8ea9d11d5a84d52b181362\"}, {\"url\": \"https://git.kernel.org/stable/c/ae99e199037c580b7350bfa3596f447a53bcf01f\"}, {\"url\": \"https://git.kernel.org/stable/c/ca2cf98d46748373e830a13d85d215d64a2d9bf2\"}, {\"url\": \"https://git.kernel.org/stable/c/e2c02a85bf53ae86d79b5fccf0a75ac0b78e0c96\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nclk: qcom: mmcc-msm8974: fix terminating of frequency table arrays\\n\\nThe frequency table arrays are supposed to be terminated with an\\nempty element. Add such entry to the end of the arrays where it\\nis missing in order to avoid possible out-of-bound access when\\nthe table is traversed by functions like qcom_find_freq() or\\nqcom_find_freq_floor().\\n\\nOnly compile tested.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.19.312\", \"versionStartIncluding\": \"3.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.274\", \"versionStartIncluding\": \"3.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.215\", \"versionStartIncluding\": \"3.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.154\", \"versionStartIncluding\": \"3.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.84\", \"versionStartIncluding\": \"3.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.24\", \"versionStartIncluding\": \"3.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.12\", \"versionStartIncluding\": \"3.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.3\", \"versionStartIncluding\": \"3.14\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9\", \"versionStartIncluding\": \"3.14\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:28:40.872Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-26965\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:28:40.872Z\", \"dateReserved\": \"2024-02-19T14:20:24.201Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-05-01T05:19:32.635Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…