
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-35924 affects the Linux kernel's USB Type-C UCSI (USB Type-C Connector System Software Interface) implementation. The vulnerability was discovered and disclosed on May 19, 2024, and involves a potential buffer overflow issue in the MESSAGE_IN region handling for UCSI versions prior to 2.0. The vulnerability specifically affects systems running Linux kernel versions that implement UCSI 1.2, where the MESSAGE_IN region size was limited to 16 bytes, compared to 256 bytes in UCSI 2.0 (Kernel Git).
The vulnerability stems from a size mismatch between UCSI versions 1.2 and 2.0, where the MESSAGE_IN region size was increased from 16 to 256 bytes. On systems running UCSI v1.2, reading larger sizes could potentially cause buffer overflows. The fix implements a mechanism to use the read UCSI version to truncate read sizes on UCSI v1.2 systems, ensuring that buffer reads are limited to the appropriate size of 16 bytes (Kernel Git).
The vulnerability could potentially lead to buffer overflows when reading from the MESSAGE_IN region on systems running UCSI v1.2. This could affect USB Type-C functionality and potentially lead to system stability issues or security vulnerabilities on affected systems (Ubuntu Security).
There are no reported instances of this vulnerability being exploited in the wild. The vulnerability requires local access to the system and interaction with the USB subsystem to potentially trigger the overflow condition (NVD).
The vulnerability has been patched in various Linux kernel versions. Ubuntu has released fixes for version 24.04 LTS (noble) with kernel version 6.8.0-38.38, and similar fixes have been implemented in other distributions. Users are advised to update their systems to the latest kernel version that includes the fix (Ubuntu Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."