CVE-2024-42237: firmware: cs_dsp: Validate payload length before processing block
firmware: csdsp: Validate payload length before processing block
Other sources
Linux Kernel is vulnerable to a denial of service, caused by improperly validating payload length in csdspload() and csdspcoeffload(). By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42237?
CVE-2024-42237 is classified as a moderate severity vulnerability affecting the Linux kernel.
What versions of Linux kernel are affected by CVE-2024-42237?
CVE-2024-42237 impacts Linux kernel versions prior to 5.16 and certain versions in the ranges 5.17 to 6.1.100, 6.2 to 6.6.41, and 6.7 to 6.9.10.
How do I fix CVE-2024-42237?
To fix CVE-2024-42237, update the Linux kernel to version 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, or 6.12.11-1 as provided in the Debian repository.
What type of vulnerability is CVE-2024-42237?
CVE-2024-42237 is a vulnerability related to insufficient payload length validation in the Linux kernel firmware processing.
Can CVE-2024-42237 be exploited by an attacker?
Yes, CVE-2024-42237 could potentially allow an attacker to manipulate firmware payloads, leading to denial of service or other unintended behaviors.