{"schema_version":"1.9.0","id":"CVE-2024-56769","published":"2025-01-06T16:20:46.838Z","modified":"2026-08-12T03:51:10.967570199Z","related":["SUSE-SU-2025:0289-1","SUSE-SU-2025:0428-1","SUSE-SU-2025:0499-1","SUSE-SU-2025:0557-1","SUSE-SU-2025:0565-1","SUSE-SU-2025:20165-1","SUSE-SU-2025:20166-1","SUSE-SU-2025:20248-1","SUSE-SU-2025:20249-1","USN-7379-2","USN-7380-1"],"summary":"media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg\n\nSyzbot reports [1] an uninitialized value issue found by KMSAN in\ndib3000_read_reg().\n\nLocal u8 rb[2] is used in i2c_transfer() as a read buffer; in case\nthat call fails, the buffer may end up with some undefined values.\n\nSince no elaborate error handling is expected in dib3000_write_reg(),\nsimply zero out rb buffer to mitigate the problem.\n\n[1] Syzkaller report\ndvb-usb: bulk message failed: -22 (6/0)\n=====================================================\nBUG: KMSAN: uninit-value in dib3000mb_attach+0x2d8/0x3c0 drivers/media/dvb-frontends/dib3000mb.c:758\n dib3000mb_attach+0x2d8/0x3c0 drivers/media/dvb-frontends/dib3000mb.c:758\n dibusb_dib3000mb_frontend_attach+0x155/0x2f0 drivers/media/usb/dvb-usb/dibusb-mb.c:31\n dvb_usb_adapter_frontend_init+0xed/0x9a0 drivers/media/usb/dvb-usb/dvb-usb-dvb.c:290\n dvb_usb_adapter_init drivers/media/usb/dvb-usb/dvb-usb-init.c:90 [inline]\n dvb_usb_init drivers/media/usb/dvb-usb/dvb-usb-init.c:186 [inline]\n dvb_usb_device_init+0x25a8/0x3760 drivers/media/usb/dvb-usb/dvb-usb-init.c:310\n dibusb_probe+0x46/0x250 drivers/media/usb/dvb-usb/dibusb-mb.c:110\n...\nLocal variable rb created at:\n dib3000_read_reg+0x86/0x4e0 drivers/media/dvb-frontends/dib3000mb.c:54\n dib3000mb_attach+0x123/0x3c0 drivers/media/dvb-frontends/dib3000mb.c:758\n...","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"74340b0a8bc60b400c7e5fe4950303aa6f914d16"},{"fixed":"035772fcd631eee2756b31cb6df249c0a8d453d7"},{"fixed":"e11778189513cd7fb2edced5bd053bc18ede8418"},{"fixed":"53106510736e734ce8b731ba871363389bfbf4c9"},{"fixed":"3876e3a1c31a58a352c6bf5d2a90e3304445a637"},{"fixed":"1d6de21f00293d819b5ca6dbe75ff1f3b6392140"},{"fixed":"c1197c1457bb7098cf46366e898eb52b41b6876a"},{"fixed":"2dd59fe0e19e1ab955259978082b62e5751924c7"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-56769.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.19"},{"fixed":"5.4.289"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.10.233"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.176"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.123"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.69"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-56769.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/035772fcd631eee2756b31cb6df249c0a8d453d7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1d6de21f00293d819b5ca6dbe75ff1f3b6392140"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2dd59fe0e19e1ab955259978082b62e5751924c7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3876e3a1c31a58a352c6bf5d2a90e3304445a637"},{"type":"WEB","url":"https://git.kernel.org/stable/c/53106510736e734ce8b731ba871363389bfbf4c9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c1197c1457bb7098cf46366e898eb52b41b6876a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e11778189513cd7fb2edced5bd053bc18ede8418"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56769.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56769"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56769.json"}}