CVE-2024-40902

Source
https://cve.org/CVERecord?id=CVE-2024-40902
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-40902.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-40902
Downstream
Related
Published
2024-07-12T12:20:43.508Z
Modified
2026-03-14T12:35:01.574771Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
jfs: xattr: fix buffer overflow for invalid xattr
Details

In the Linux kernel, the following vulnerability has been resolved:

jfs: xattr: fix buffer overflow for invalid xattr

When an xattr size is not what is expected, it is printed out to the kernel log in hex format as a form of debugging. But when that xattr size is bigger than the expected size, printing it out can cause an access off the end of the buffer.

Fix this all up by properly restricting the size of the debug hex dump in the kernel log.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/40xxx/CVE-2024-40902.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
f0dedb5c511ed82cbaff4997a8decf2351ba549f
Fixed
1e84c9b1838152a87cf453270a5fa75c5037e83a
Fixed
fc745f6e83cb650f9a5f2c864158e3a5ea76dad0
Fixed
480e5bc21f2c42d90c2c16045d64d824dcdd5ec7
Fixed
33aecc5799c93d3ee02f853cb94e201f9731f123
Fixed
4598233d9748fe4db4e13b9f473588aa25e87d69
Fixed
b537cb2f4c4a1357479716a9c339c0bda03d873f
Fixed
7c55b78818cfb732680c4a72ab270cc2d2ee3d0f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-40902.json"