Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2024-42086— iio: chemical: bme680: Fix overflows in compensate() functions

EPSS 0.03% · P8

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinux1b3bd8592780c87c5eddabbe98666b086bbaee36< 6fa31bbe2ea8665ee970258eb8320cbf231dbe9eaffected
1b3bd8592780c87c5eddabbe98666b086bbaee36< b0af334616ed425024bf220adda0f004806b5febaffected
1b3bd8592780c87c5eddabbe98666b086bbaee36< c326551e99f5416986074ce78bef94f6a404b517affected
1b3bd8592780c87c5eddabbe98666b086bbaee36< 7a13d1357658d3a3c1cd7b3b9543c805a6e5e6e9affected
1b3bd8592780c87c5eddabbe98666b086bbaee36< ba1bb3e2a38a7fef1c1818dd4f2d9abbfdde553aaffected
1b3bd8592780c87c5eddabbe98666b086bbaee36< b5967393d50e3c6e632efda3ea3fdde14c1bfd0eaffected
1b3bd8592780c87c5eddabbe98666b086bbaee36< 3add41bbda92938e9a528d74659dfc552796be4eaffected
1b3bd8592780c87c5eddabbe98666b086bbaee36< fdd478c3ae98c3f13628e110dce9b6cfb0d9b3c8affected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-42086

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
iio: chemical: bme680: Fix overflows in compensate() functions
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: iio: chemical: bme680: Fix overflows in compensate() functions There are cases in the compensate functions of the driver that there could be overflows of variables due to bit shifting ops. These implications were initially discussed here [1] and they were mentioned in log message of Commit 1b3bd8592780 ("iio: chemical: Add support for Bosch BME680 sensor"). [1]: https://lore.kernel.org/linux-iio/20180728114028.3c1bbe81@archlinux/
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在补偿函数中,由于位移操作,变量可能会溢出。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 1b3bd8592780c87c5eddabbe98666b086bbaee36 ~ 6fa31bbe2ea8665ee970258eb8320cbf231dbe9e -
LinuxLinux 4.19 -

II. Public POCs for CVE-2024-42086

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-42086

登录查看更多情报信息。

Same Patch Batch · Linux · 2024-07-29 · 121 CVEs total

CVE-2024-41088can: mcp251xfd: fix infinite loop when xmit fails
CVE-2024-42067bpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro()
CVE-2024-42066drm/xe: Fix potential integer overflow in page size calculation
CVE-2024-42065drm/xe: Add a NULL check in xe_ttm_stolen_mgr_init
CVE-2024-42063bpf: Mark bpf prog stack with kmsan_unposion_memory in interpreter mode
CVE-2024-42064drm/amd/display: Skip pipe if the pipe idx not set properly
CVE-2023-52887net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rts_s
CVE-2024-41098ata: libata-core: Fix null pointer dereference on error
CVE-2024-41097usb: atm: cxacru: fix endpoint checking in cxacru_bind()
CVE-2024-41096PCI/MSI: Fix UAF in msi_capability_init
CVE-2024-41095drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_ld_modes
CVE-2024-41094drm/fbdev-dma: Only set smem_start is enable per module option
CVE-2024-41093drm/amdgpu: avoid using null object of framebuffer
CVE-2024-41092drm/i915/gt: Fix potential UAF by revoke of fence registers
CVE-2024-41089drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes
CVE-2024-41077null_blk: fix validation of block size
CVE-2024-41080io_uring: fix possible deadlock in io_register_iowq_max_workers()
CVE-2024-41079nvmet: always initialize cqe.result
CVE-2024-41078btrfs: qgroup: fix quota root leak after quota disable failure
CVE-2024-41075cachefiles: add consistency check for copen/cread

Showing top 20 of 121 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-42086

No comments yet


Leave a comment