CVE-2024-27401 (GCVE-0-2024-27401)
Vulnerability from cvelistv5
Published
2024-05-13 10:29
Modified
2026-08-05 11:29
Summary
In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_length is taken into account when fetching packet contents Ensure that packet_buffer_get respects the user_length provided. If the length of the head packet exceeds the user_length, packet_buffer_get will now return 0 to signify to the user that no data were read and a larger buffer size is required. Helps prevent user space overflows.
Impacted products
Vendor Product Version
Linux Linux Version: 286468210d83ce0ca1e37e346ed9f4457a161650
Version: 286468210d83ce0ca1e37e346ed9f4457a161650
Version: 286468210d83ce0ca1e37e346ed9f4457a161650
Version: 286468210d83ce0ca1e37e346ed9f4457a161650
Version: 286468210d83ce0ca1e37e346ed9f4457a161650
Version: 286468210d83ce0ca1e37e346ed9f4457a161650
Version: 286468210d83ce0ca1e37e346ed9f4457a161650
Version: 286468210d83ce0ca1e37e346ed9f4457a161650
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-27401",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-05-13T17:55:43.034157Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-07-05T17:21:00.939Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T00:34:52.126Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/67f34f093c0f7bf33f5b4ae64d3d695a3b978285"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/7b8c7bd2296e95b38a6ff346242356a2e7190239"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/cca330c59c54207567a648357835f59df9a286bb"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/79f988d3ffc1aa778fc5181bdfab312e57956c6b"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/4ee0941da10e8fdcdb34756b877efd3282594c1f"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/1fe60ee709436550f8cfbab01295936b868d5baa"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/539d51ac48bcfcfa1b3d4a85f8df92fa22c1d41c"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/38762a0763c10c24a4915feee722d7aa6e73eb98"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OTB4HWU2PTVW5NEYHHLOCXDKG3PYA534/"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DW2MIOIMOFUSNLHLRYX23AFR36BMKD65/"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/firewire/nosy.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "67f34f093c0f7bf33f5b4ae64d3d695a3b978285",
              "status": "affected",
              "version": "286468210d83ce0ca1e37e346ed9f4457a161650",
              "versionType": "git"
            },
            {
              "lessThan": "7b8c7bd2296e95b38a6ff346242356a2e7190239",
              "status": "affected",
              "version": "286468210d83ce0ca1e37e346ed9f4457a161650",
              "versionType": "git"
            },
            {
              "lessThan": "cca330c59c54207567a648357835f59df9a286bb",
              "status": "affected",
              "version": "286468210d83ce0ca1e37e346ed9f4457a161650",
              "versionType": "git"
            },
            {
              "lessThan": "79f988d3ffc1aa778fc5181bdfab312e57956c6b",
              "status": "affected",
              "version": "286468210d83ce0ca1e37e346ed9f4457a161650",
              "versionType": "git"
            },
            {
              "lessThan": "4ee0941da10e8fdcdb34756b877efd3282594c1f",
              "status": "affected",
              "version": "286468210d83ce0ca1e37e346ed9f4457a161650",
              "versionType": "git"
            },
            {
              "lessThan": "1fe60ee709436550f8cfbab01295936b868d5baa",
              "status": "affected",
              "version": "286468210d83ce0ca1e37e346ed9f4457a161650",
              "versionType": "git"
            },
            {
              "lessThan": "539d51ac48bcfcfa1b3d4a85f8df92fa22c1d41c",
              "status": "affected",
              "version": "286468210d83ce0ca1e37e346ed9f4457a161650",
              "versionType": "git"
            },
            {
              "lessThan": "38762a0763c10c24a4915feee722d7aa6e73eb98",
              "status": "affected",
              "version": "286468210d83ce0ca1e37e346ed9f4457a161650",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/firewire/nosy.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.36"
            },
            {
              "lessThan": "2.6.36",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.314",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.276",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.217",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.159",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.91",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.31",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.10",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.9",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.314",
                  "versionStartIncluding": "2.6.36",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.276",
                  "versionStartIncluding": "2.6.36",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.217",
                  "versionStartIncluding": "2.6.36",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.159",
                  "versionStartIncluding": "2.6.36",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.91",
                  "versionStartIncluding": "2.6.36",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.31",
                  "versionStartIncluding": "2.6.36",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.10",
                  "versionStartIncluding": "2.6.36",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9",
                  "versionStartIncluding": "2.6.36",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: nosy: ensure user_length is taken into account when fetching packet contents\n\nEnsure that packet_buffer_get respects the user_length provided. If\nthe length of the head packet exceeds the user_length, packet_buffer_get\nwill now return 0 to signify to the user that no data were read\nand a larger buffer size is required. Helps prevent user space overflows."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is triggered by a local `read(2)` syscall on the `/dev/nosy` character device, where the caller supplies the undersized `user_length` that the kernel then ignores. Although the overflowing bytes originate from the IEEE 1394 bus, the vulnerable code path itself is entered and controlled entirely through a local file-descriptor operation.\nAC:L - The attacker simply calls `read()` with a small `count` while any traffic is present on the snooped 1394 bus (cycle-start packets alone arrive every 125 \u00b5s, and a bus reset queues a packet), making the overflow reliably and repeatedly reproducible with no memory-layout or timing conditions outside the attacker\u0027s control.\nPR:L - `nosy.c` contains no capability or permission checks whatsoever \u2014 reachability is decided solely by the permissions on `/dev/nosy`, which on the developer, lab, embedded and protocol-analysis systems where this sniffer is deployed is routinely opened up to a non-root group or passed into a container. Choosing the higher-severity option between L and H, an ordinary unprivileged user with the device node is sufficient.\nUI:N - The attacker performs the `read()` themselves and needs no victim action; the overflow occurs as soon as a packet longer than the supplied buffer is dequeued. No mount, no file open by another user, no configuration change by an administrator is required.\nS:U - The out-of-bounds write lands inside the address space of the process that issued the `read()`, and the compromised resources belong to the same security authority as the vulnerable kernel component. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - `nosy_read()` returns a length greater than the requested `count`, so a caller following the standard read idiom consumes, prints, or logs memory located beyond its own buffer \u2014 an unbounded disclosure of adjacent process memory (heap pointers, keys, buffered data). The accompanying memory corruption is further leverageable to leak state from a privileged reader.\nI:H - Up to roughly 8 KB of externally supplied 1394 packet bytes are written past the end of the caller\u0027s stack or heap buffer, giving a large, content-controlled out-of-bounds write. Overwriting adjacent objects, saved registers, or function pointers in a nosy consumer that customarily runs as root yields control-flow hijack and arbitrary modification.\nA:H - The overflow reliably smashes adjacent memory and will SIGSEGV or abort the reading process (typically a root sniffer/logging daemon), and the copy can also fault mid-transfer leaving the buffer state inconsistent. Repeated triggering keeps the affected service permanently down."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:29:34.613Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/67f34f093c0f7bf33f5b4ae64d3d695a3b978285"
        },
        {
          "url": "https://git.kernel.org/stable/c/7b8c7bd2296e95b38a6ff346242356a2e7190239"
        },
        {
          "url": "https://git.kernel.org/stable/c/cca330c59c54207567a648357835f59df9a286bb"
        },
        {
          "url": "https://git.kernel.org/stable/c/79f988d3ffc1aa778fc5181bdfab312e57956c6b"
        },
        {
          "url": "https://git.kernel.org/stable/c/4ee0941da10e8fdcdb34756b877efd3282594c1f"
        },
        {
          "url": "https://git.kernel.org/stable/c/1fe60ee709436550f8cfbab01295936b868d5baa"
        },
        {
          "url": "https://git.kernel.org/stable/c/539d51ac48bcfcfa1b3d4a85f8df92fa22c1d41c"
        },
        {
          "url": "https://git.kernel.org/stable/c/38762a0763c10c24a4915feee722d7aa6e73eb98"
        }
      ],
      "title": "firewire: nosy: ensure user_length is taken into account when fetching packet contents",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-27401",
    "datePublished": "2024-05-13T10:29:53.862Z",
    "dateReserved": "2024-02-25T13:47:42.681Z",
    "dateUpdated": "2026-08-05T11:29:34.613Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/67f34f093c0f7bf33f5b4ae64d3d695a3b978285\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/7b8c7bd2296e95b38a6ff346242356a2e7190239\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/cca330c59c54207567a648357835f59df9a286bb\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/79f988d3ffc1aa778fc5181bdfab312e57956c6b\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/4ee0941da10e8fdcdb34756b877efd3282594c1f\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/1fe60ee709436550f8cfbab01295936b868d5baa\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/539d51ac48bcfcfa1b3d4a85f8df92fa22c1d41c\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/38762a0763c10c24a4915feee722d7aa6e73eb98\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OTB4HWU2PTVW5NEYHHLOCXDKG3PYA534/\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DW2MIOIMOFUSNLHLRYX23AFR36BMKD65/\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T00:34:52.126Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-27401\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-05-13T17:55:43.034157Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-07-05T15:20:37.572Z\"}}], \"cna\": {\"title\": \"firewire: nosy: ensure user_length is taken into account when fetching packet contents\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerability is triggered by a local `read(2)` syscall on the `/dev/nosy` character device, where the caller supplies the undersized `user_length` that the kernel then ignores. Although the overflowing bytes originate from the IEEE 1394 bus, the vulnerable code path itself is entered and controlled entirely through a local file-descriptor operation.\\nAC:L - The attacker simply calls `read()` with a small `count` while any traffic is present on the snooped 1394 bus (cycle-start packets alone arrive every 125 \\u00b5s, and a bus reset queues a packet), making the overflow reliably and repeatedly reproducible with no memory-layout or timing conditions outside the attacker\u0027s control.\\nPR:L - `nosy.c` contains no capability or permission checks whatsoever \\u2014 reachability is decided solely by the permissions on `/dev/nosy`, which on the developer, lab, embedded and protocol-analysis systems where this sniffer is deployed is routinely opened up to a non-root group or passed into a container. Choosing the higher-severity option between L and H, an ordinary unprivileged user with the device node is sufficient.\\nUI:N - The attacker performs the `read()` themselves and needs no victim action; the overflow occurs as soon as a packet longer than the supplied buffer is dequeued. No mount, no file open by another user, no configuration change by an administrator is required.\\nS:U - The out-of-bounds write lands inside the address space of the process that issued the `read()`, and the compromised resources belong to the same security authority as the vulnerable kernel component. No VM, IOMMU, or sandbox boundary is crossed.\\nC:H - `nosy_read()` returns a length greater than the requested `count`, so a caller following the standard read idiom consumes, prints, or logs memory located beyond its own buffer \\u2014 an unbounded disclosure of adjacent process memory (heap pointers, keys, buffered data). The accompanying memory corruption is further leverageable to leak state from a privileged reader.\\nI:H - Up to roughly 8 KB of externally supplied 1394 packet bytes are written past the end of the caller\u0027s stack or heap buffer, giving a large, content-controlled out-of-bounds write. Overwriting adjacent objects, saved registers, or function pointers in a nosy consumer that customarily runs as root yields control-flow hijack and arbitrary modification.\\nA:H - The overflow reliably smashes adjacent memory and will SIGSEGV or abort the reading process (typically a root sniffer/logging daemon), and the copy can also fault mid-transfer leaving the buffer state inconsistent. Repeated triggering keeps the affected service permanently down.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"286468210d83ce0ca1e37e346ed9f4457a161650\", \"lessThan\": \"67f34f093c0f7bf33f5b4ae64d3d695a3b978285\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"286468210d83ce0ca1e37e346ed9f4457a161650\", \"lessThan\": \"7b8c7bd2296e95b38a6ff346242356a2e7190239\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"286468210d83ce0ca1e37e346ed9f4457a161650\", \"lessThan\": \"cca330c59c54207567a648357835f59df9a286bb\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"286468210d83ce0ca1e37e346ed9f4457a161650\", \"lessThan\": \"79f988d3ffc1aa778fc5181bdfab312e57956c6b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"286468210d83ce0ca1e37e346ed9f4457a161650\", \"lessThan\": \"4ee0941da10e8fdcdb34756b877efd3282594c1f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"286468210d83ce0ca1e37e346ed9f4457a161650\", \"lessThan\": \"1fe60ee709436550f8cfbab01295936b868d5baa\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"286468210d83ce0ca1e37e346ed9f4457a161650\", \"lessThan\": \"539d51ac48bcfcfa1b3d4a85f8df92fa22c1d41c\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"286468210d83ce0ca1e37e346ed9f4457a161650\", \"lessThan\": \"38762a0763c10c24a4915feee722d7aa6e73eb98\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/firewire/nosy.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"2.6.36\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"2.6.36\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"4.19.314\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"4.19.*\"}, {\"status\": \"unaffected\", \"version\": \"5.4.276\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.217\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.159\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.91\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.31\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.10\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/firewire/nosy.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/67f34f093c0f7bf33f5b4ae64d3d695a3b978285\"}, {\"url\": \"https://git.kernel.org/stable/c/7b8c7bd2296e95b38a6ff346242356a2e7190239\"}, {\"url\": \"https://git.kernel.org/stable/c/cca330c59c54207567a648357835f59df9a286bb\"}, {\"url\": \"https://git.kernel.org/stable/c/79f988d3ffc1aa778fc5181bdfab312e57956c6b\"}, {\"url\": \"https://git.kernel.org/stable/c/4ee0941da10e8fdcdb34756b877efd3282594c1f\"}, {\"url\": \"https://git.kernel.org/stable/c/1fe60ee709436550f8cfbab01295936b868d5baa\"}, {\"url\": \"https://git.kernel.org/stable/c/539d51ac48bcfcfa1b3d4a85f8df92fa22c1d41c\"}, {\"url\": \"https://git.kernel.org/stable/c/38762a0763c10c24a4915feee722d7aa6e73eb98\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nfirewire: nosy: ensure user_length is taken into account when fetching packet contents\\n\\nEnsure that packet_buffer_get respects the user_length provided. If\\nthe length of the head packet exceeds the user_length, packet_buffer_get\\nwill now return 0 to signify to the user that no data were read\\nand a larger buffer size is required. Helps prevent user space overflows.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.19.314\", \"versionStartIncluding\": \"2.6.36\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.276\", \"versionStartIncluding\": \"2.6.36\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.217\", \"versionStartIncluding\": \"2.6.36\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.159\", \"versionStartIncluding\": \"2.6.36\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.91\", \"versionStartIncluding\": \"2.6.36\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.31\", \"versionStartIncluding\": \"2.6.36\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.10\", \"versionStartIncluding\": \"2.6.36\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9\", \"versionStartIncluding\": \"2.6.36\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:29:34.613Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-27401\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:29:34.613Z\", \"dateReserved\": \"2024-02-25T13:47:42.681Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-05-13T10:29:53.862Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…