CVE-2024-49902

In the Linux kernel, the following vulnerability has been resolved: jfs: check if leafidx greater than num leaves per dmap tree syzbot report a out of bounds in dbSplit, it because dmt_leafidx greater than num leaves per dmap tree, add a checking for dmt_leafidx in dbFindLeaf. Shaggy: Modified sanity check to apply to control pages as well as leaf pages.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

13 Nov 2024, 13:47

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/058aa89b3318be3d66a103ba7c68d717561e1dc6 - () https://git.kernel.org/stable/c/058aa89b3318be3d66a103ba7c68d717561e1dc6 - Patch
References () https://git.kernel.org/stable/c/2451e5917c56be45d4add786e2a059dd9c2c37c4 - () https://git.kernel.org/stable/c/2451e5917c56be45d4add786e2a059dd9c2c37c4 - Patch
References () https://git.kernel.org/stable/c/25d2a3ff02f22e215ce53355619df10cc5faa7ab - () https://git.kernel.org/stable/c/25d2a3ff02f22e215ce53355619df10cc5faa7ab - Patch
References () https://git.kernel.org/stable/c/35b91f15f44ce3c01eba058ccb864bb04743e792 - () https://git.kernel.org/stable/c/35b91f15f44ce3c01eba058ccb864bb04743e792 - Patch
References () https://git.kernel.org/stable/c/4a7bf6a01fb441009a6698179a739957efd88e38 - () https://git.kernel.org/stable/c/4a7bf6a01fb441009a6698179a739957efd88e38 - Patch
References () https://git.kernel.org/stable/c/7fff9a9f866e99931cf6fa260288e55d01626582 - () https://git.kernel.org/stable/c/7fff9a9f866e99931cf6fa260288e55d01626582 - Patch
References () https://git.kernel.org/stable/c/cb0eb10558802764f07de1dc439c4609e27cb4f0 - () https://git.kernel.org/stable/c/cb0eb10558802764f07de1dc439c4609e27cb4f0 - Patch
References () https://git.kernel.org/stable/c/d64ff0d2306713ff084d4b09f84ed1a8c75ecc32 - () https://git.kernel.org/stable/c/d64ff0d2306713ff084d4b09f84ed1a8c75ecc32 - Patch
References () https://git.kernel.org/stable/c/d76b9a4c283c7535ae7c7c9b14984e75402951e1 - () https://git.kernel.org/stable/c/d76b9a4c283c7535ae7c7c9b14984e75402951e1 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

08 Nov 2024, 16:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/35b91f15f44ce3c01eba058ccb864bb04743e792 -
  • () https://git.kernel.org/stable/c/d76b9a4c283c7535ae7c7c9b14984e75402951e1 -

23 Oct 2024, 15:13

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: jfs: comprobar si leafidx es mayor que la cantidad de hojas por árbol dmap syzbot informa que dbSplit está fuera de los límites, esto se debe a que dmt_leafidx es mayor que la cantidad de hojas por árbol dmap, se agrega una verificación para dmt_leafidx en dbFindLeaf. Shaggy: Se modificó la verificación de cordura para que se aplique a las páginas de control y a las páginas de hoja.

21 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-21 18:15

Updated : 2024-11-13 13:47


NVD link : CVE-2024-49902

Mitre link : CVE-2024-49902

CVE.ORG link : CVE-2024-49902


JSON object : View

Products Affected

linux

  • linux_kernel