CVE Vulnerabilities

CVE-2024-11263

Privilege Context Switching Error

Published: Nov 15, 2024 | Modified: Feb 03, 2025
CVSS 3.x
8.4
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which is then used by the linker to relax accesses to global symbols.

Weakness

The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.

Affected Software

Name Vendor Start Version End Version
Zephyr Zephyrproject * 3.7.0 (including)

Potential Mitigations

References