hwmon: (coretemp) Fix out-of-bounds memory access

Summary

CVECVE-2024-26664
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2024-04-02 07:15:43 UTC
Updated2026-08-04 11:16:55 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access Fix a bug that pdata->cpu_map[] is set before out-of-bounds check. The problem might be triggered on systems with more than 128 cores per package.

Risk And Classification

Primary CVSS: v3.1 7.1 HIGH from [email protected]

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Problem Types: CWE-787


VersionSourceTypeScoreSeverityVector
3.1[email protected]Primary7.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3.1CNADECLARED7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 4f9dcadc55c21b39b072bb0882362c7edc4340bc 93f0f4e846fcb682c3ec436e3b2e30e5a3a8ee6a git Not specified
CNA Linux Linux affected c00cdfc9bd767ee743ad3a4054de17aeb0afcbca 1eb74c00c9c3b13cb65e508c5d5a2f11afb96b8b git Not specified
CNA Linux Linux affected d9f0159da05df869071164edf0c6d7302efc5eca f0da068c75c20ffc5ba28243ff577531dc2af1fd git Not specified
CNA Linux Linux affected 30cf0dee372baf9b515f2d9c7218f905fddf3cdb a16afec8e83c56b14a4a73d2e3fb8eec3a8a057e git Not specified
CNA Linux Linux affected 7108b80a542b9d65e44b36d64a700a83658c0b73 9bce69419271eb8b2b3ab467387cb59c99d80deb git Not specified
CNA Linux Linux affected 7108b80a542b9d65e44b36d64a700a83658c0b73 853a6503c586a71abf27e60a7f8c4fb28092976d git Not specified
CNA Linux Linux affected 7108b80a542b9d65e44b36d64a700a83658c0b73 3a7753bda55985dc26fae17795cb10d825453ad1 git Not specified
CNA Linux Linux affected 7108b80a542b9d65e44b36d64a700a83658c0b73 4e440abc894585a34c2904a32cd54af1742311b3 git Not specified
CNA Linux Linux affected d1de8e1ae924d9dc31548676e4a665b52ebee27e git Not specified
CNA Linux Linux affected 4.19.264 4.19.307 semver Not specified
CNA Linux Linux affected 5.4.221 5.4.269 semver Not specified
CNA Linux Linux affected 5.10.152 5.10.210 semver Not specified
CNA Linux Linux affected 5.15.76 5.15.149 semver Not specified
CNA Linux Linux affected 6.0.6 6.1 semver Not specified
CNA Linux Linux affected 6.1 Not specified
CNA Linux Linux unaffected 6.1 semver Not specified
CNA Linux Linux unaffected 4.19.307 4.19.* semver Not specified
CNA Linux Linux unaffected 5.4.269 5.4.* semver Not specified
CNA Linux Linux unaffected 5.10.210 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.149 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.78 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.17 6.6.* semver Not specified
CNA Linux Linux unaffected 6.7.5 6.7.* semver Not specified
CNA Linux Linux unaffected 6.8 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/4e440abc894585a34c2904a32cd54af1742311b3 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
lists.debian.org/debian-lts-announce/2024/06/msg00017.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org Mailing List
git.kernel.org/stable/c/93f0f4e846fcb682c3ec436e3b2e30e5a3a8ee6a af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/1eb74c00c9c3b13cb65e508c5d5a2f11afb96b8b af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/3a7753bda55985dc26fae17795cb10d825453ad1 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/853a6503c586a71abf27e60a7f8c4fb28092976d af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
lists.debian.org/debian-lts-announce/2024/06/msg00020.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org Mailing List
git.kernel.org/stable/c/9bce69419271eb8b2b3ab467387cb59c99d80deb af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/f0da068c75c20ffc5ba28243ff577531dc2af1fd af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/a16afec8e83c56b14a4a73d2e3fb8eec3a8a057e af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 6000567 Debian Security Update for linux (DSA 5658-1)

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report