HomeDefectsLIN1023-4197
Fixed

LIN1023-4197 : Security Advisory - linux - CVE-2023-52601

Created: Mar 7, 2024    Updated: Apr 27, 2024
Resolved Date: Apr 19, 2024
Found In Version: 10.23.30.1
Fix Version: 10.23.30.9
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

jfs: fix array-index-out-of-bounds in dbAdjTree

Currently there is a bound check missing in the dbAdjTree while
accessing the dmt_stree. To add the required check added the bool is_ctl
which is required to determine the size as suggest in the following
commit.
https://lore.kernel.org/linux-kernel-mentees/f9475918-2186-49b8-b801-6f0f9e75f4fa@oracle.com/

CREATE(Triage):(User=admin) CVE-2023-52601 (https://nvd.nist.gov/vuln/detail/CVE-2023-52601)

CVEs