CVE-2024-56557

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Dec 27, 2024
Updated: Feb 18, 2025
CWE ID 120

Summary

CVE-2024-56557 is a newly identified vulnerability affecting the Linux kernel's iio driver for the AD7923 Analog-to-Digital Converter. The issue arises due to the insufficient size adjustment of the 'tx_buf' and 'ring_xfer' buffers when updating the driver to support 8-channel devices. This oversight could potentially result in a buffer overflow in the 'ad7923_update_scan_mode()' function. The vulnerability has been addressed in the latest kernel updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share