CVE-2024-39462·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: clk: bcm: dvp: Assign ->num before accessing ->hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with __counted_by") annotated the hws member of 'struct clk_hw_onecell_data' with __counted_by, which informs the bounds sanitizer about the number of elements in hws, so that it can warn when hws is accessed out of bounds. As noted in that change, the __counted_by member must be initialized with the number of elements before the first array access happens, otherwise there will be a warning from each access prior to the initialization because the number of elements is zero. This occurs in clk_dvp_probe() due to ->num being assigned after ->hws has been accessed: UBSAN: array-index-out-of-bounds in drivers/clk/bcm/clk-bcm2711-dvp.c:59:2 index 0 is out of range for type 'struct clk_hw *[] __counted_by(num)' (aka 'struct clk_hw *[]') Move the ->num initialization to before the first access of ->hws, which clears up the warning.
- Severity
- critical
- Software
- Kernel
- Fixed in
- 6.9.5
- Published
- 2024-06-25
Affected versions
From: 6.7
Until: 6.9.5
Fixed in: 6.9.5
How to fix this CVE
Update the Linux kernel to version 6.9.5 or later to resolve this array bounds validation issue in the Broadcom DVP clock driver. The vulnerability stems from improper initialization order where the array element count is assigned after the array is first accessed, triggering bounds checker warnings. Systems running kernel versions 6.7 through 6.9.4 should prioritize this update immediately.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check installed kernel version: uname -r
- Verify if Broadcom DVP clock driver is in use: lsmod | grep clk_bcm2711_dvp or cat /sys/module/clk_bcm2711_dvp/version
- Search system logs for UBSAN warnings: dmesg | grep -i 'array-index-out-of-bounds.*clk-bcm2711-dvp' or journalctl -b | grep -i 'array-index-out-of-bounds'
- Confirm patch status by checking kernel compile flags: cat /boot/config-$(uname -r) | grep -i bcm2711 and verify kernel version is 6.9.5 or later
FAQ
What is CVE-2024-39462?
This vulnerability affects the Broadcom DVP clock driver in the Linux kernel where the array size counter is initialized after array elements are accessed, causing undefined behavior detection warnings and potential kernel instability.
Is CVE-2024-39462 being actively exploited?
No, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog and no public exploits are available. However, the critical CVSS score warrants prompt patching.
What versions of Kernel are affected by CVE-2024-39462?
Linux kernel versions 6.7 through 6.9.4 are affected. Version 6.9.5 and later contain the fix.
How do I check if my server is vulnerable to CVE-2024-39462?
Run 'uname -r' to check your kernel version. If it reports 6.7.x through 6.9.4, you are vulnerable. Additionally, run 'dmesg | grep -c array-index-out-of-bounds' to detect if the issue is actively occurring.
Does Defensia detect CVE-2024-39462?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel package is installed on a monitored server, CVE-2024-39462 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/0dc913217fb79096597005bba9ba738e2db5cd02
- https://git.kernel.org/stable/c/9368cdf90f52a68120d039887ccff74ff33b4444
- https://git.kernel.org/stable/c/a1dd92fca0d6b58b55ed0484f75d4205dbb77010
- https://git.kernel.org/stable/c/0dc913217fb79096597005bba9ba738e2db5cd02
- https://git.kernel.org/stable/c/9368cdf90f52a68120d039887ccff74ff33b4444
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-39462. Free for 1 server.
Get started free