{"id":"ASB-A-349777785","details":"In multiq_tune of sch_multiq.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-349777785","CVE-2024-36978"],"modified":"2026-05-22T15:55:21.353668239Z","published":"2024-11-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2024-11-01"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/841cae881066f0dd38d15a90cfcf245b0db9fc73"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/89bc0b3e94aca316922ea2c1fa95efb7b935a9dd"}],"affected":[{"package":{"name":":linux_kernel:","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":":0"},{"fixed":":2024-11-05"}]}],"versions":["Kernel"],"ecosystem_specific":{"spl":"2024-11-05","fixes":["https://android.googlesource.com/kernel/common/+/841cae881066f0dd38d15a90cfcf245b0db9fc73","https://android.googlesource.com/kernel/common/+/89bc0b3e94aca316922ea2c1fa95efb7b935a9dd"],"types":["EoP"],"vanir_signatures":[{"signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/841cae881066f0dd38d15a90cfcf245b0db9fc73","digest":{"line_hashes":["116836023247365727830807583073258796829","293186181438904796417585315409241229877","193681609402722915796820278242998607810","268184959904940014411019765210601625268"],"threshold":0.9},"id":"ASB-A-349777785-fbe94967","deprecated":false,"signature_type":"Line","target":{"file":"net/sched/sch_multiq.c"}}],"severity":"High"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-349777785.json"}}],"schema_version":"1.7.5"}