CVE-2024-57983
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-57983 is a newly identified vulnerability affecting the Linux kernel. The issue lies in the mailbox driver th1520, where the functions th1520_mbox_suspend_noirq and th1520_mbox_resume_noirq are intended to save and restore interrupt mask registers in the MBOX ICU0. However, the array used to store these registers was incorrectly sized, leading to memory corruption when accessing all four registers during suspend and resume operations. This vulnerability has been resolved by correcting the array size in the latest kernel update to prevent potential memory corruption.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX