Wind River Support Network

HomeDefectsLIN1021-14313
Acknowledged

LIN1021-14313 : Security Advisory - linux - CVE-2024-58010

Created: Feb 27, 2025    Updated: Jun 17, 2025
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

binfmt_flat: Fix integer overflow bug on 32 bit systems

Most of these sizes and counts are capped at 256MB so the math doesn't
result in an integer overflow.  The "relocs" count needs to be checked
as well.  Otherwise on 32bit systems the calculation of "full_data"
could be wrong.

        full_data = data_len + relocs * sizeof(unsigned long);

CREATE(Triage):(User=admin) CVE-2024-58010 (https://nvd.nist.gov/vuln/detail/CVE-2024-58010)
Live chat
Online