{"dataType":"CVE_RECORD","cveMetadata":{"cveId":"CVE-2024-36016","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-17T13:50:33.154Z","datePublished":"2024-05-29T18:46:34.778Z","dateUpdated":"2026-08-05T11:31:37.096Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:31:37.096Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntty: n_gsm: fix possible out-of-bounds in gsm0_receive()\n\nAssuming the following:\n- side A configures the n_gsm in basic option mode\n- side B sends the header of a basic option mode frame with data length 1\n- side A switches to advanced option mode\n- side B sends 2 data bytes which exceeds gsm->len\n  Reason: gsm->len is not used in advanced option mode.\n- side A switches to basic option mode\n- side B keeps sending until gsm0_receive() writes past gsm->buf\n  Reason: Neither gsm->state nor gsm->len have been reset after\n  reconfiguration.\n\nFix this by changing gsm->count to gsm->len comparison from equal to less\nthan. Also add upper limit checks against the constant MAX_MRU in\ngsm0_receive() and gsm1_receive() to harden against memory corruption of\ngsm->len and gsm->mru.\n\nAll other checks remain as we still need to limit the data according to the\nuser configuration and actual payload size."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation is entirely local — the attacker opens /dev/ptmx, attaches the N_GSM0710 line discipline via TIOCSETD, drives mode switches with the GSMIOC_SETCONF ioctl, and feeds the malicious byte stream by writing to the pty master. No network or physical access is involved.\nAC:L - The attacker controls both sides of the pty pair, so the exact sequence (fill count in advanced mode, reconfigure to basic mode, keep writing) is deterministic and requires no race or unpredictable memory state. A tested proof of concept was attached to the upstream bug report (bugzilla 218708).\nPR:L - Across most of the affected range (2.6.35 through 6.5, and stable trees prior to the Aug-2023 backport of 67c37756898a), attaching N_GSM0710 required no privileges whatsoever, and GSMIOC_SETCONF has no capability check at all — so a plain unprivileged local account with a pty is sufficient.\nUI:N - The attacker performs every step — ldisc attach, reconfiguration, and data injection — without any action by another user or victim process.\nS:U - The heap corruption occurs in kernel memory belonging to the same security authority as the kernel itself; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The desynced count/len are also used by gsm_fcs_add_block() and dlci->data(dlci, gsm->buf, gsm->len), producing out-of-bounds reads whose contents are delivered into DLCI tty buffers the attacker can read back, and the heap overflow primitive can be leveraged for broader kernel memory disclosure.\nI:H - This is an unbounded linear heap buffer overflow past a 1501-byte kmalloc'd object with fully attacker-controlled bytes and attacker-chosen length, giving control over adjacent kmalloc-2k slab objects — a strong primitive for arbitrary write and control-flow hijacking.\nA:H - Overwriting arbitrary amounts of adjacent slab memory reliably corrupts kernel data structures and slab metadata, causing oops or panic; the reporter observed memory corruption in practice."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/tty/n_gsm.c"],"versions":[{"version":"e1eaea46bb4020b38a141b84f88565d4603f8dd0","lessThan":"9513d4148950b05bc99fa7314dc883cc0e1605e5","status":"affected","versionType":"git"},{"version":"e1eaea46bb4020b38a141b84f88565d4603f8dd0","lessThan":"b229bc6c6ea9fe459fc3fa94fd0a27a2f32aca56","status":"affected","versionType":"git"},{"version":"e1eaea46bb4020b38a141b84f88565d4603f8dd0","lessThan":"0fb736c9931e02dbc7d9a75044c8e1c039e50f04","status":"affected","versionType":"git"},{"version":"e1eaea46bb4020b38a141b84f88565d4603f8dd0","lessThan":"4c267110fc110390704cc065edb9817fdd10ff54","status":"affected","versionType":"git"},{"version":"e1eaea46bb4020b38a141b84f88565d4603f8dd0","lessThan":"46f52c89a7e7d2691b97a9728e4591d071ca8abc","status":"affected","versionType":"git"},{"version":"e1eaea46bb4020b38a141b84f88565d4603f8dd0","lessThan":"774d83b008eccb1c48c14dc5486e7aa255731350","status":"affected","versionType":"git"},{"version":"e1eaea46bb4020b38a141b84f88565d4603f8dd0","lessThan":"f126ce7305fe88f49cdabc6db4168b9318898ea3","status":"affected","versionType":"git"},{"version":"e1eaea46bb4020b38a141b84f88565d4603f8dd0","lessThan":"b890d45aaf02b564e6cae2d2a590f9649330857d","status":"affected","versionType":"git"},{"version":"e1eaea46bb4020b38a141b84f88565d4603f8dd0","lessThan":"47388e807f85948eefc403a8a5fdc5b406a65d5a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/tty/n_gsm.c"],"versions":[{"version":"2.6.35","status":"affected"},{"version":"0","lessThan":"2.6.35","status":"unaffected","versionType":"semver"},{"version":"4.19.316","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.278","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.219","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.161","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.93","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.33","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.8.12","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9.3","lessThanOrEqual":"6.9.*","status":"unaffected","versionType":"semver"},{"version":"6.10","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"4.19.316"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"5.4.278"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"5.10.219"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"5.15.161"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.1.93"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.6.33"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.8.12"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.9.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.10"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9513d4148950b05bc99fa7314dc883cc0e1605e5"},{"url":"https://git.kernel.org/stable/c/b229bc6c6ea9fe459fc3fa94fd0a27a2f32aca56"},{"url":"https://git.kernel.org/stable/c/0fb736c9931e02dbc7d9a75044c8e1c039e50f04"},{"url":"https://git.kernel.org/stable/c/4c267110fc110390704cc065edb9817fdd10ff54"},{"url":"https://git.kernel.org/stable/c/46f52c89a7e7d2691b97a9728e4591d071ca8abc"},{"url":"https://git.kernel.org/stable/c/774d83b008eccb1c48c14dc5486e7aa255731350"},{"url":"https://git.kernel.org/stable/c/f126ce7305fe88f49cdabc6db4168b9318898ea3"},{"url":"https://git.kernel.org/stable/c/b890d45aaf02b564e6cae2d2a590f9649330857d"},{"url":"https://git.kernel.org/stable/c/47388e807f85948eefc403a8a5fdc5b406a65d5a"}],"title":"tty: n_gsm: fix possible out-of-bounds in gsm0_receive()","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-125","lang":"en","description":"CWE-125 Out-of-bounds Read"}]}],"affected":[{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"e1eaea46bb40","status":"affected","lessThan":"b890d45aaf02","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"e1eaea46bb40","status":"affected","lessThan":"47388e807f85","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:2.6.35:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"2.6.35","status":"affected"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"e1eaea46bb40","status":"affected","lessThan":"f126ce7305fe","versionType":"custom"},{"version":"e1eaea46bb40","status":"affected","lessThan":"9513d4148950","versionType":"custom"},{"version":"e1eaea46bb40","status":"affected","lessThan":"b229bc6c6ea9","versionType":"custom"},{"version":"e1eaea46bb40","status":"affected","lessThan":"0fb736c9931e","versionType":"custom"},{"version":"e1eaea46bb40","status":"affected","lessThan":"4c267110fc11","versionType":"custom"},{"version":"e1eaea46bb40","status":"affected","lessThanOrEqual":"46f52c89a7e7","versionType":"custom"},{"version":"e1eaea46bb40","status":"affected","lessThan":"774d83b008ec","versionType":"custom"},{"version":"0","status":"unaffected","lessThan":"2.6.35","versionType":"custom"},{"version":"4.19.316","status":"unaffected","lessThanOrEqual":"4.20","versionType":"custom"},{"version":"5.4.278","status":"unaffected","lessThanOrEqual":"5.5","versionType":"custom"},{"version":"5.10.219","status":"unaffected","lessThanOrEqual":"5.11","versionType":"custom"},{"version":"5.15.161","status":"unaffected","lessThanOrEqual":"5.16","versionType":"custom"},{"version":"6.1.93","status":"unaffected","lessThanOrEqual":"6.2","versionType":"custom"},{"version":"6.6.33","status":"unaffected","lessThanOrEqual":"6.7","versionType":"custom"},{"version":"6.8.12","status":"unaffected","lessThanOrEqual":"6.9","versionType":"custom"},{"version":"6.9.3","status":"unaffected","lessThanOrEqual":"6.10","versionType":"custom"},{"version":"6.10","status":"unaffected","lessThanOrEqual":"*","versionType":"custom"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.7,"attackVector":"LOCAL","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-05-30T18:00:26.164343Z","id":"CVE-2024-36016","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-08-22T17:58:33.311Z"}},{"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/9513d4148950b05bc99fa7314dc883cc0e1605e5","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/b229bc6c6ea9fe459fc3fa94fd0a27a2f32aca56","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/0fb736c9931e02dbc7d9a75044c8e1c039e50f04","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/4c267110fc110390704cc065edb9817fdd10ff54","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/46f52c89a7e7d2691b97a9728e4591d071ca8abc","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/774d83b008eccb1c48c14dc5486e7aa255731350","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/f126ce7305fe88f49cdabc6db4168b9318898ea3","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/b890d45aaf02b564e6cae2d2a590f9649330857d","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/47388e807f85948eefc403a8a5fdc5b406a65d5a","tags":["x_transferred"]},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-04T17:20:57.711Z"}}]},"dataVersion":"5.2"}