CVE-2024-38381

Source
https://cve.org/CVERecord?id=CVE-2024-38381
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-38381.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-38381
Downstream
Related
Published
2024-06-21T10:18:12.302Z
Modified
2026-03-23T05:10:02.448152226Z
Summary
nfc: nci: Fix uninit-value in nci_rx_work
Details

In the Linux kernel, the following vulnerability has been resolved:

nfc: nci: Fix uninit-value in ncirxwork

syzbot reported the following uninit-value access issue [1]

ncirxwork() parses received packet from ndev->rx_q. It should be validated header size, payload size and total packet size before processing the packet. If an invalid packet is detected, it should be silently discarded.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38381.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
11387b2effbb55f58dc2111ef4b4b896f2756240
Fixed
406cfac9debd4a6d3dc5d9258ee086372a8c08b6
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
03fe259649a551d336a7f20919b641ea100e3fff
Fixed
485ded868ed62ceb2acb3a459d7843fd71472619
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
755e53bbc61bc1aff90eafa64c8c2464fd3dfa3c
Fixed
f80b786ab0550d0020191a59077b2c7e069db2d1
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ac68d9fa09e410fa3ed20fb721d56aa558695e16
Fixed
ad4d196d2008c7f413167f0a693feb4f0439d7fe
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b51ec7fc9f877ef869c01d3ea6f18f6a64e831a7
Fixed
e8c8e0d0d214c877fbad555df5b3ed558cd9b0c3
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a946ebee45b09294c8b0b0e77410b763c4d2817a
Fixed
e53a7f8afcbd2886f2a94c5d56757328109730ea
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d24b03535e5eb82e025219c2f632b485409c898f
Fixed
017ff397624930fd7ac7f1761f3c9d6a7100f68c
Fixed
e4a87abf588536d1cdfb128595e6e680af5cf3ed
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
8948e30de81faee87eeee01ef42a1f6008f5a83a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-38381.json"