CVE-2024-38587: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: speakup: Fix sizeof() vs ARRAY_SIZE() bug The "buf" pointer is an array of u16 values. This code should be using ARRAY_SIZE() (which is 256) instead of sizeof() (which is 512), otherwise it can the still got out of bounds.
Affected products
- Linux Linux Kernel: from 4.19.313, before 4.19.316 (fixed in 4.19.316); from 5.4.275, before 5.4.278 (fixed in 5.4.278); from 5.10.216, before 5.10.219 (fixed in 5.10.219); from 5.15.157, before 5.15.161 (fixed in 5.15.161); from 6.1.88, before 6.1.93 (fixed in 6.1.93); from 6.6.29, before 6.6.33 (fixed in 6.6.33); …
Published 2024-06-19. Last modified 2026-08-04.