---
cve: "CVE-2024-46774"
severity: "LOW"
cvss: 3.1
epss: "24%"
vendor: "Linux"
kev: false
exploited: false
published: "2024-09-18 08:15:05"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T00:37:07+02:00"
---

# CVE-2024-46774

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

powerpc/rtas: Prevent Spectre v1 gadget construction in sys_rtas()

Smatch warns:

  arch/powerpc/kernel/rtas.c:1932 __do_sys_rtas() warn: potential
  spectre issue 'args.args' [r] (local cap)

The 'nargs' and 'nret' locals come directly from a user-supplied
buffer and are used as indexes into a small stack-based array and as
inputs to copy_to_user() after they are subject to bounds checks.

Use array_index_nospec() after the bounds checks to clamp these values
for speculative execution.

## Patch verfügbar (OSV)

- Kernel ≥ 5.10.237
- Kernel ≥ 5.15.181
- Kernel ≥ 6.1.135
- Kernel ≥ 6.6.88
- Kernel ≥ 6.10.10

## Referenzen

- <https://git.kernel.org/stable/c/d2834ff1d9641a8695a09ea79cd901c7b6d4d05f>
- <https://git.kernel.org/stable/c/a262c2dc833f2fe1bd5c53a4d899e7077d3b1da9>
- <https://git.kernel.org/stable/c/b137af795399d8b657bad1646c18561530f35ed1>
- <https://git.kernel.org/stable/c/1f1feff02e9da0dd0cdb195c428c42b5f9b6c771>
- <https://git.kernel.org/stable/c/68d8156480940b79227d58865ec5d2947b9384a8>
- <https://git.kernel.org/stable/c/0974d03eb479384466d828d65637814bee6b26d7>
- <https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-46774) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
