CVE-2024-27008: Debian Linux

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm: nv04: Fix out of bounds access When Output Resource (dcb->or) value is assigned in fabricate_dcb_output(), there may be out of bounds access to dac_users array in case dcb->or is zero because ffs(dcb->or) is used as index there. The 'or' argument of fabricate_dcb_output() must be interpreted as a number of bit to set, not value. Utilize macros from 'enum nouveau_or' in calls instead of hardcoding. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 38 only; version 39 only; version 40 only
  • Linux Linux Kernel: from 2.6.38, before 4.19.313 (fixed in 4.19.313); from 4.20, before 5.4.275 (fixed in 5.4.275); from 5.5, before 5.10.216 (fixed in 5.10.216); from 5.11, before 5.15.157 (fixed in 5.15.157); from 5.16, before 6.1.88 (fixed in 6.1.88); from 6.2, before 6.6.29 (fixed in 6.6.29); …

Published 2024-05-01. Last modified 2026-06-17.