jfs: xattr: fix buffer overflow for invalid xattr
Published Jul 12, 2024
7.8
HIGHCVSS 3.1
EPSS 0.32%
Description
When an xattr size is not what is expected, it is printed out to the kernel log in hex format as a form of debugging. But when that xattr size is bigger than the expected size, printing it out can cause an access off the end of the buffer.
Fix this all up by properly restricting the size of the debug hex dump in the kernel log.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.12
- Version 4.19.317StatusunaffectedConstraints<=4.19.*
- Version 5.10.221StatusunaffectedConstraints<=5.10.*
- Version 5.15.162StatusunaffectedConstraints<=5.15.*
- Version 5.4.279StatusunaffectedConstraints<=5.4.*
- Version 6.1.95StatusunaffectedConstraints<=6.1.*
- Version 6.10StatusunaffectedConstraints<=*
- Version 6.6.35StatusunaffectedConstraints<=6.6.*
- Version 6.9.6StatusunaffectedConstraints<=6.9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- < 4.19.317
- ≥ 4.20 · < 5.4.279
- ≥ 5.5 · < 5.10.221
- ≥ 5.11 · < 5.15.162
- ≥ 5.16 · < 6.1.95
- ≥ 6.2 · < 6.6.35
- ≥ 6.7 · < 6.9.6
- 6.10
- 6.10
- 6.10
-
- Version 1da177e4c3f4StatusaffectedConstraints<1e84c9b18381
- Version 1da177e4c3f4StatusaffectedConstraints<33aecc5799c9
- Version 1da177e4c3f4StatusaffectedConstraints<4598233d9748
- Version 1da177e4c3f4StatusaffectedConstraints<480e5bc21f2c
- Version 1da177e4c3f4StatusaffectedConstraints<7c55b78818cf
- Version 1da177e4c3f4StatusaffectedConstraints<b537cb2f4c4a
- Version 1da177e4c3f4StatusaffectedConstraints<f0dedb5c511e
- Version 1da177e4c3f4StatusaffectedConstraints<fc745f6e83cb
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux Kernel | unaffected |
|
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (14)
- https://access.redhat.com/security/cve/CVE-2024-40902 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2297486 Issue Tracking
- https://git.kernel.org/stable/c/1e84c9b1838152a87cf453270a5fa75c5037e83a Patch
- https://git.kernel.org/stable/c/33aecc5799c93d3ee02f853cb94e201f9731f123 Patch
- https://git.kernel.org/stable/c/4598233d9748fe4db4e13b9f473588aa25e87d69 Patch
- https://git.kernel.org/stable/c/480e5bc21f2c42d90c2c16045d64d824dcdd5ec7 Patch
- https://git.kernel.org/stable/c/7c55b78818cfb732680c4a72ab270cc2d2ee3d0f Patch
- https://git.kernel.org/stable/c/b537cb2f4c4a1357479716a9c339c0bda03d873f Patch
- https://git.kernel.org/stable/c/f0dedb5c511ed82cbaff4997a8decf2351ba549f Patch
- https://git.kernel.org/stable/c/fc745f6e83cb650f9a5f2c864158e3a5ea76dad0 Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lore.kernel.org/linux-cve-announce/2024071207-CVE-2024-40902-122a@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-40902
- https://www.cve.org/CVERecord?id=CVE-2024-40902
Change history (0)
No recorded changes yet.