In the Linux kernel, the following vulnerability has been resolved:
jfs: Fix uninit-value access of new_ea in ea_buffer
syzbot reports that lzo1x_1_do_compress is using uninit-value:
=====================================================
BUG: KMSAN: uninit-value in lzo1x_1_do_compress+0x19f9/0x2510 lib/lzo/lzo1x_compress.c:178
...
Uninit was stored to memory at:
ea_put fs/jfs/xattr.c:639 [inline]
...
Local variable ea_buf created at:
__jfs_setxattr+0x5d/0x1ae0 fs/jfs/xattr.c:662
__jfs_xattr_set+0xe6/0x1f0 fs/jfs/xattr.c:934
=====================================================
The reason is ea_buf->new_ea is not initialized properly.
Fix this by using memset to empty its content at the beginning
in ea_get().
References
Configurations
Configuration 1 (hide)
|
History
08 Nov 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
25 Oct 2024, 14:24
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-908 | |
CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
First Time |
Linux linux Kernel
Linux |
|
References | () https://git.kernel.org/stable/c/2b59ffad47db1c46af25ccad157bb3b25147c35c - Patch | |
References | () https://git.kernel.org/stable/c/6041536d18c5f51a84bc37cd568cbab61870031e - Patch | |
References | () https://git.kernel.org/stable/c/7c244d5b48284a770d96ff703df2dfeadf804a73 - Patch | |
References | () https://git.kernel.org/stable/c/8ad8b531de79c348bcb8133e7f5e827b884226af - Patch | |
References | () https://git.kernel.org/stable/c/8b1dcf25c26d42e4a68c4725ce52a0543c7878cc - Patch | |
References | () https://git.kernel.org/stable/c/c076b3746224982eebdba5c9e4b1467e146c0d64 - Patch | |
References | () https://git.kernel.org/stable/c/d7444f91a9f93eaa48827087ed0f3381c194181d - Patch |
23 Oct 2024, 15:13
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
21 Oct 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-21 18:15
Updated : 2024-11-08 16:15
NVD link : CVE-2024-49900
Mitre link : CVE-2024-49900
CVE.ORG link : CVE-2024-49900
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-908
Use of Uninitialized Resource