clk: qcom: mmcc-apq8084: fix terminating of frequency table arrays
Summary
| CVE | CVE-2024-26966 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-05-01 06:15:12 UTC |
| Updated | 2026-08-04 11:17:28 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: clk: qcom: mmcc-apq8084: fix terminating of frequency table arrays The frequency table arrays are supposed to be terminated with an empty element. Add such entry to the end of the arrays where it is missing in order to avoid possible out-of-bound access when the table is traversed by functions like qcom_find_freq() or qcom_find_freq_floor(). Only compile tested. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-129
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd 5533686e99b04994d7c4877dc0e4282adc9444a2 git | Not specified |
| CNA | Linux | Linux | affected 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd b2dfb216f32627c2f6a8041f2d9d56d102ab87c0 git | Not specified |
| CNA | Linux | Linux | affected 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd a09aecb6cb482de88301c43bf00a6c8726c4d34f git | Not specified |
| CNA | Linux | Linux | affected 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd 3aedcf3755c74dafc187eb76acb04e3e6348b1a9 git | Not specified |
| CNA | Linux | Linux | affected 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd 185de0b7cdeaad8b89ebd4c8a258ff2f21adba99 git | Not specified |
| CNA | Linux | Linux | affected 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd 9b4c4546dd61950e80ffdca1bf6925f42b665b03 git | Not specified |
| CNA | Linux | Linux | affected 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd 7e5432401536117c316d7f3b21d46b64c1514f38 git | Not specified |
| CNA | Linux | Linux | affected 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd 5638330150db2cc30b53eed04e481062faa3ece8 git | Not specified |
| CNA | Linux | Linux | affected 2b46cd23a5a2cf0b8d3583338b63409f5e78e7cd a903cfd38d8dee7e754fb89fd1bebed99e28003d git | Not specified |
| CNA | Linux | Linux | affected 3.17 | Not specified |
| CNA | Linux | Linux | unaffected 3.17 semver | Not specified |
| CNA | Linux | Linux | unaffected 4.19.312 4.19.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.274 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.215 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.154 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.84 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.24 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.7.12 6.7.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.8.3 6.8.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.9 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/185de0b7cdeaad8b89ebd4c8a258ff2f21adba99 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2024/06/msg00017.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List, Third Party Advisory |
| git.kernel.org/stable/c/b2dfb216f32627c2f6a8041f2d9d56d102ab87c0 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/5638330150db2cc30b53eed04e481062faa3ece8 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/9b4c4546dd61950e80ffdca1bf6925f42b665b03 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/7e5432401536117c316d7f3b21d46b64c1514f38 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/5533686e99b04994d7c4877dc0e4282adc9444a2 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/a903cfd38d8dee7e754fb89fd1bebed99e28003d | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/3aedcf3755c74dafc187eb76acb04e3e6348b1a9 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/a09aecb6cb482de88301c43bf00a6c8726c4d34f | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2024/06/msg00020.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.