U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-36477

Change History

New CVE Received by NIST 6/21/2024 8:15:11 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer

The TPM SPI transfer mechanism uses MAX_SPI_FRAMESIZE for computing the
maximum transfer length and the size of the transfer buffer. As such, it
does not account for the 4 bytes of header that prepends the SPI data
frame. This can result in out-of-bounds accesses and was confirmed with
KASAN.

Introduce SPI_HDRSIZE to account for the header and use to allocate the
transfer buffer.
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/1547183852dcdfcc25878db7dd3620509217b0cd [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/195aba96b854dd664768f382cd1db375d8181f88 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/de13c56f99477b56980c7e00b09c776d16b7563d [No types assigned]