CVE-2024-41059
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/07/2024
Last modified:
03/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
hfsplus: fix uninit-value in copy_name<br />
<br />
[syzbot reported]<br />
BUG: KMSAN: uninit-value in sized_strscpy+0xc4/0x160<br />
sized_strscpy+0xc4/0x160<br />
copy_name+0x2af/0x320 fs/hfsplus/xattr.c:411<br />
hfsplus_listxattr+0x11e9/0x1a50 fs/hfsplus/xattr.c:750<br />
vfs_listxattr fs/xattr.c:493 [inline]<br />
listxattr+0x1f3/0x6b0 fs/xattr.c:840<br />
path_listxattr fs/xattr.c:864 [inline]<br />
__do_sys_listxattr fs/xattr.c:876 [inline]<br />
__se_sys_listxattr fs/xattr.c:873 [inline]<br />
__x64_sys_listxattr+0x16b/0x2f0 fs/xattr.c:873<br />
x64_sys_call+0x2ba0/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:195<br />
do_syscall_x64 arch/x86/entry/common.c:52 [inline]<br />
do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83<br />
entry_SYSCALL_64_after_hwframe+0x77/0x7f<br />
<br />
Uninit was created at:<br />
slab_post_alloc_hook mm/slub.c:3877 [inline]<br />
slab_alloc_node mm/slub.c:3918 [inline]<br />
kmalloc_trace+0x57b/0xbe0 mm/slub.c:4065<br />
kmalloc include/linux/slab.h:628 [inline]<br />
hfsplus_listxattr+0x4cc/0x1a50 fs/hfsplus/xattr.c:699<br />
vfs_listxattr fs/xattr.c:493 [inline]<br />
listxattr+0x1f3/0x6b0 fs/xattr.c:840<br />
path_listxattr fs/xattr.c:864 [inline]<br />
__do_sys_listxattr fs/xattr.c:876 [inline]<br />
__se_sys_listxattr fs/xattr.c:873 [inline]<br />
__x64_sys_listxattr+0x16b/0x2f0 fs/xattr.c:873<br />
x64_sys_call+0x2ba0/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:195<br />
do_syscall_x64 arch/x86/entry/common.c:52 [inline]<br />
do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83<br />
entry_SYSCALL_64_after_hwframe+0x77/0x7f<br />
[Fix]<br />
When allocating memory to strbuf, initialize memory to 0.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.19.319 (excluding) | |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.20 (including) | 5.4.281 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 5.10.223 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.164 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.101 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.42 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.9.11 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0570730c16307a72f8241df12363f76600baf57d
- https://git.kernel.org/stable/c/22999936b91ba545ce1fbbecae6895127945e91c
- https://git.kernel.org/stable/c/34f8efd2743f2d961e92e8e994de4c7a2f9e74a0
- https://git.kernel.org/stable/c/72805debec8f7aa342da194fe0ed7bc8febea335
- https://git.kernel.org/stable/c/ad57dc2caf1e0a3c0a9904400fae7afbc9f74bb2
- https://git.kernel.org/stable/c/c733e24a61cbcff10f660041d6d84d32bb7e4cb4
- https://git.kernel.org/stable/c/d02d8c1dacafb28930c39e16d48e40bb6e4cbc70
- https://git.kernel.org/stable/c/f08956d8e0f80fd0d4ad84ec917302bb2f3a9c6a
- https://git.kernel.org/stable/c/0570730c16307a72f8241df12363f76600baf57d
- https://git.kernel.org/stable/c/22999936b91ba545ce1fbbecae6895127945e91c
- https://git.kernel.org/stable/c/34f8efd2743f2d961e92e8e994de4c7a2f9e74a0
- https://git.kernel.org/stable/c/72805debec8f7aa342da194fe0ed7bc8febea335
- https://git.kernel.org/stable/c/ad57dc2caf1e0a3c0a9904400fae7afbc9f74bb2
- https://git.kernel.org/stable/c/c733e24a61cbcff10f660041d6d84d32bb7e4cb4
- https://git.kernel.org/stable/c/d02d8c1dacafb28930c39e16d48e40bb6e4cbc70
- https://git.kernel.org/stable/c/f08956d8e0f80fd0d4ad84ec917302bb2f3a9c6a
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html



