CVE-2024-26981

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/05/2024
Last modified:
04/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nilfs2: fix OOB in nilfs_set_de_type<br /> <br /> The size of the nilfs_type_by_mode array in the fs/nilfs2/dir.c file is<br /> defined as "S_IFMT &gt;&gt; S_SHIFT", but the nilfs_set_de_type() function,<br /> which uses this array, specifies the index to read from the array in the<br /> same way as "(mode &amp; S_IFMT) &gt;&gt; S_SHIFT".<br /> <br /> static void nilfs_set_de_type(struct nilfs_dir_entry *de, struct inode<br /> *inode)<br /> {<br /> umode_t mode = inode-&gt;i_mode;<br /> <br /> de-&gt;file_type = nilfs_type_by_mode[(mode &amp; S_IFMT)&gt;&gt;S_SHIFT]; // oob<br /> }<br /> <br /> However, when the index is determined this way, an out-of-bounds (OOB)<br /> error occurs by referring to an index that is 1 larger than the array size<br /> when the condition "mode &amp; S_IFMT == S_IFMT" is satisfied. Therefore, a<br /> patch to resize the nilfs_type_by_mode array should be applied to prevent<br /> OOB errors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.30 (including) 4.19.313 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.20 (including) 5.4.275 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.216 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.157 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.88 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.29 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.8.8 (excluding)
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools