CVE-2024-3979

Source
https://cve.org/CVERecord?id=CVE-2024-3979
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-3979.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-3979
Published
2024-04-19T18:00:08.395Z
Modified
2026-07-15T01:49:18.311665694Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
Summary
COVESA vsomeip race condition
Details

A vulnerability, which was classified as problematic, has been found in COVESA vsomeip up to 3.4.10. Affected by this issue is some unknown functionality. The manipulation leads to race condition. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261596.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "3.4.0"
                },
                {
                    "last_affected": "3.4.0"
                },
                {
                    "introduced": "3.4.2"
                },
                {
                    "last_affected": "3.4.2"
                },
                {
                    "introduced": "3.4.3"
                },
                {
                    "last_affected": "3.4.3"
                },
                {
                    "introduced": "3.4.4"
                },
                {
                    "last_affected": "3.4.4"
                },
                {
                    "introduced": "3.4.5"
                },
                {
                    "last_affected": "3.4.5"
                },
                {
                    "introduced": "3.4.6"
                },
                {
                    "last_affected": "3.4.6"
                },
                {
                    "introduced": "3.4.7"
                },
                {
                    "last_affected": "3.4.7"
                },
                {
                    "introduced": "3.4.8"
                },
                {
                    "last_affected": "3.4.8"
                }
            ]
        }
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/3xxx/CVE-2024-3979.json",
    "cwe_ids": [
        "CWE-362"
    ]
}
References

Affected packages

Git / github.com/covesa/vsomeip

Affected ranges

Type
GIT
Repo
https://github.com/covesa/vsomeip
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "3.4.1"
        },
        {
            "last_affected": "3.4.1"
        },
        {
            "introduced": "3.4.10"
        },
        {
            "last_affected": "3.4.10"
        },
        {
            "introduced": "3.4.9"
        },
        {
            "last_affected": "3.4.9"
        }
    ]
}

Affected versions

3.*
3.4.1
3.4.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-3979.json"