vulnerability

Oracle Linux: CVE-2024-42223: ELSA-2024-12610: Unbreakable Enterprise kernel security update (IMPORTANT) (Multiple Advisories)

Severity
5
CVSS
(AV:L/AC:L/Au:S/C:N/I:N/A:C)
Published
Jul 30, 2024
Added
Oct 16, 2024
Modified
May 26, 2025

Description

In the Linux kernel, the following vulnerability has been resolved:
media: dvb-frontends: tda10048: Fix integer overflow
state->xtal_hz can be up to 16M, so it can overflow a 32 bit integer
when multiplied by pll_mfactor.
Create a new 64 bit variable to hold the calculations.
A vulnerability was found in the Linux kernel's tda10048 driver in the tda10048_set_if() function, where the improperly sized variable state->xtal_hz can lead to an integer overflow during a multiplication operation. This issue can lead to an incorrect value calculation impacting the driver and the dvb system's functionality.

Solution

oracle-linux-upgrade-kernel-uek
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.