Wind River Support Network

HomeDefectsLIN1023-7032
Fixed

LIN1023-7032 : Security Advisory - linux - CVE-2024-40902

Created: Jul 13, 2024    Updated: Jul 25, 2024
Resolved Date: Jul 14, 2024
Found In Version: 10.23.30.1
Fix Version: 10.23.30.12
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

jfs: xattr: fix buffer overflow for invalid xattr

When an xattr size is not what is expected, it is printed out to the
kernel log in hex format as a form of debugging.  But when that xattr
size is bigger than the expected size, printing it out can cause an
access off the end of the buffer.

Fix this all up by properly restricting the size of the debug hex dump
in the kernel log.

CREATE(Triage):(User=admin) CVE-2024-40902 (https://nvd.nist.gov/vuln/detail/CVE-2024-40902)

CVEs


Live chat
Online