← Browse

CVE-2024-26969

Medium

Elevated severity or exploit probability.

CVSS base
7.3 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
EPSS — probability of exploitation (30 days)
0.3%
17.7th percentile
CISA KEV
Not listed
Weakness / dates
CWE-129
Published 2024-05-01 · modified 2026-08-04

CVSS breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H

Attack VectorLLocal
Attack ComplexityLLow
Privileges RequiredLLow
User InteractionNNone
ScopeUUnchanged
ConfidentialityHHigh
IntegrityLLow
AvailabilityHHigh

Timeline

Description

In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gcc-ipq8074: fix terminating of frequency table arrays The frequency table arrays are supposed to be terminated with an empty element. Add such entry to the end of the arrays where it is missing in order to avoid possible out-of-bound access when the table is traversed by functions like qcom_find_freq() or qcom_find_freq_floor(). Only compile tested.

Affected

debian linux

References

Official: NVD · CVE.org