Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_420xx - fix off by one in uof_get_name() This is called from uof_get_name_420xx() where "num_objs" is the ARRAY_SIZE() of fw_objs[]. The > needs to be >= to prevent an out of bounds access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.8, < 6.11.11 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/91eef1ad75f03d37dba926b73f9dd6f058bc4d58Patch
- https://git.kernel.org/stable/c/93a11608fb3720e1bc2b19a2649ac2b49cca1921Patch
- https://git.kernel.org/stable/c/c23661a36eea840b657e485d48ed88b246da1bb8Patch
FAQ
What is CVE-2024-53163?
CVE-2024-53163 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_420xx - fix off by one in uof_get_name() This is called from uof_get_name_420xx() where "num_objs" is the ARRAY_SI...
How severe is CVE-2024-53163?
CVE-2024-53163 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-53163?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.