Wind River Support Network

HomeDefectsLIN1024-2701
Fixed

LIN1024-2701 : Security Advisory - linux - CVE-2024-40902

Created: Jul 13, 2024    Updated: Aug 28, 2024
Resolved Date: Jul 14, 2024
Found In Version: 10.24.33.1
Fix Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

jfs: xattr: fix buffer overflow for invalid xattr

When an xattr size is not what is expected, it is printed out to the
kernel log in hex format as a form of debugging.  But when that xattr
size is bigger than the expected size, printing it out can cause an
access off the end of the buffer.

Fix this all up by properly restricting the size of the debug hex dump
in the kernel log.

CREATE(Triage):(User=admin) CVE-2024-40902 (https://nvd.nist.gov/vuln/detail/CVE-2024-40902)

CVEs


Live chat
Online