Cyber Resilience

CVE-2024-43843

Linux Kernel 6.8 – 6.10.3

Published
17 August 2024
Modified
29 October 2024
Patch / advisory
CVSS Score v3.1 7.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0020 11th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2024-43843 is a high-severity Incorrect Calculation of Buffer Size (CWE-131) vulnerability in Linux Linux Kernel. Its CVSS base score is 7.8 (High).

Operationally, ranked at the 11th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix out-of-bounds issue when preparing trampoline image We get the size of the trampoline image during the dry run phase and allocate memory based on that size. The…

more

allocated image will then be populated with instructions during the real patch phase. But after commit 26ef208c209a ("bpf: Use arch_bpf_trampoline_size"), the `im` argument is inconsistent in the dry run and real patch phase. This may cause emit_imm in RV64 to generate a different number of instructions when generating the 'im' address, potentially causing out-of-bounds issues. Let's emit the maximum number of instructions for the "im" address during dry run to fix this problem.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-42259Same product: Linux Linux Kernel
CVE-2026-43107Same product: Linux Linux Kernel
CVE-2024-46684Same product: Linux Linux Kernel
CVE-2024-26721Same product: Linux Linux Kernel
CVE-2026-43302Same product: Linux Linux Kernel
CVE-2026-53091Same product: Linux Linux Kernel
CVE-2024-46729Same product: Linux Linux Kernel
CVE-2026-43501Same product: Linux Linux Kernel
CVE-2026-53143Same product: Linux Linux Kernel
CVE-2026-52955Same product: Linux Linux Kernel

Affected Assets

linux
linux kernel
6.8 — 6.10.3

Mitigating Controls

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly prevent buffer-size miscalculations via coding standards, reviews, and testing, while fixing this single weakness only partially fulfills the broader control.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

degrades

Secure coding standards directly require correct buffer-size calculations.

detects

Security testing can detect buffer-size errors before release.

prevents

Secure development lifecycle mandates size-checking practices that reduce buffer-size miscalculations.

prevents

Application security requirements can specify buffer-size validation rules.

prevents

Secure architecture principles include safe memory-allocation guidelines.

References