ocfs2: add bounds checking to ocfs2_check_dir_entry()
Published Jul 29, 2024
7.8
HIGHCVSS 3.1
EPSS 0.25%
Description
This adds sanity checks for ocfs2_dir_entry to make sure all members of ocfs2_dir_entry don't stray beyond valid memory region.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.24StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.24
- Version 4.19.319StatusunaffectedConstraints<=4.19.*
- Version 5.10.223StatusunaffectedConstraints<=5.10.*
- Version 5.15.164StatusunaffectedConstraints<=5.15.*
- Version 5.4.281StatusunaffectedConstraints<=5.4.*
- Version 6.1.102StatusunaffectedConstraints<=6.1.*
- Version 6.10.2StatusunaffectedConstraints<=6.10.*
- Version 6.11StatusunaffectedConstraints<=*
- Version 6.6.43StatusunaffectedConstraints<=6.6.*
- Version 6.9.12StatusunaffectedConstraints<=6.9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- < 4.19.319
- ≥ 4.20 · < 5.4.281
- ≥ 5.5 · < 5.10.223
- ≥ 5.11 · < 5.15.164
- ≥ 5.16 · < 6.1.102
- ≥ 6.2 · < 6.6.43
- ≥ 6.7 · < 6.9.12
- ≥ 6.10 · < 6.10.2
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not vulnerable to this CVE, as it does not affect the versions or configurations of the Linux kernel used in its distributions.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (16)
- https://access.redhat.com/security/cve/CVE-2024-41015 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2300298 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-39364 Advisory
- https://git.kernel.org/stable/c/13d38c00df97289e6fba2e54193959293fd910d2 Patch
- https://git.kernel.org/stable/c/255547c6bb8940a97eea94ef9d464ea5967763fb Patch
- https://git.kernel.org/stable/c/53de17ad01cb5f6f8426f597e9d5c87d4cf53bb7 Patch
- https://git.kernel.org/stable/c/564d23cc5b216211e1694d53f7e45959396874d0 Patch
- https://git.kernel.org/stable/c/624b380074f0dc209fb8706db3295c735079f34c Patch
- https://git.kernel.org/stable/c/77495e5da5cb110a8fed27b052c77853fe282176 Patch
- https://git.kernel.org/stable/c/e05a24289db90f76ff606086aadd62d068a88dcd Patch
- https://git.kernel.org/stable/c/edb2e67dd4626b06fd7eb37252d5067912e78d59 Patch
- https://git.kernel.org/stable/c/fd65685594ee707cbf3ddf22ebb73697786ac114 Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lore.kernel.org/linux-cve-announce/2024072910-CVE-2024-41015-e5c0@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-41015
- https://www.cve.org/CVERecord?id=CVE-2024-41015
Change history (0)
No recorded changes yet.