CVE-2024-38631: iio: adc: PAC1934: fix accessing out of bounds array index
In the Linux kernel, the following vulnerability has been resolved:
iio: adc: PAC1934: fix accessing out of bounds array index
Fix accessing out of bounds array index for average
current and voltage measurements. The device itself has
only 4 channels, but in sysfs there are "fake"
channels for the average voltages and currents too.
Security readout for executives and security teams
Plain-English summary
This is a Linux kernel driver flaw in the PAC1934 power-monitoring ADC driver. The driver could access an array outside its intended bounds when handling average voltage and current sysfs channels. Business urgency depends on whether affected Linux kernels and PAC1934 hardware or driver support exist in your fleet.
Executive priority
Treat as targeted kernel maintenance unless PAC1934-backed devices are deployed in production. Prioritize embedded, industrial, monitoring, or appliance environments over standard server fleets.
Technical view
The issue is an out-of-bounds array index in the Linux kernel IIO ADC PAC1934 driver. The device has four real channels, while sysfs exposes additional fake average-current and average-voltage channels. The sources identify stable kernel commits as the resolution but do not state impact, privilege requirements, or exploitability.
Likely exposure
Exposure appears limited to Linux systems running affected kernel versions with the PAC1934 driver relevant or enabled. General-purpose servers without this hardware or driver path are less likely to be exposed, but fleet inventory is needed.
Exploitation context
The provided sources do not report active exploitation, and the CVE is not listed as KEV. No public exploit status, attacker prerequisites, or demonstrated impact are provided in the bundle.
Researcher notes
Evidence is sparse: no CVSS, CWE, privilege model, or impact classification is supplied. The strongest facts are the kernel subsystem, the out-of-bounds index condition, fake sysfs average channels, and the two stable fix references.
Mitigation direction
Update to a kernel build containing the referenced stable fixes.
Check Linux distribution advisories for patched kernel packages.
Prioritize systems using PAC1934 hardware or the PAC1934 driver.
If unused, review vendor guidance on disabling the driver.
Validation and detection
Inventory Linux kernel versions across affected device classes.
Check whether the PAC1934 driver is present, loaded, or packaged.
Confirm patched builds include the referenced stable commits.
Review sysfs exposure only on authorized test systems.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-38631 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.