In the Linux kernel, the following vulnerability has been resolved:
jfs: don't walk off the end of ealist
Add a check before visiting the members of ea to make sure each ea stays within the ealist.
{ "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Function", "target": { "file": "fs/jfs/xattr.c", "function": "jfs_listxattr" }, "deprecated": false, "digest": { "length": 880.0, "function_hash": "112841498775573498117924276806373409502" }, "id": "CVE-2024-41017-01cc3a5d", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7f91bd0f2941fa36449ce1a15faaa64f840d9746" }, { "signature_version": "v1", "signature_type": "Line", "target": { "file": "fs/jfs/xattr.c" }, "deprecated": false, "digest": { "line_hashes": [ "308544276059562008642344751349671253058", "332889882221938267698944684769674649453", "323585934589071353542814791306068729493", "323293562209655894456809467673995358571", "97900349366480261157158558344841555081", "22523298367176732825474565255654489690", "119151116356278847791525370345103906774", "59119815036124814882066691536728043995", "26729843576558839132835022943968859600", "36243336417894233531793917648263485421", "193167999141198017891242991167834158472", "327133548672119411743190974297631847730", "151088234726763817957219904661878347967", "334955521348071046428878538888823398423", "70135975923178363094730363177488094702", "34488156798232700945607798128452488233", "141705826914729364372109159686684658664", "104482820914375734667426691630246889150", "292600880089204384931409969705264260612", "250942862949487023120284698504777499889", "141409178003407268252992673634988586452", "336797069635513997736757398274002959850" ], "threshold": 0.9 }, "id": "CVE-2024-41017-1838f38a", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7e21574195a45fc193555fa40e99fed16565ff7e" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "fs/jfs/xattr.c", "function": "__jfs_getxattr" }, "deprecated": false, "digest": { "length": 924.0, "function_hash": "196754699848022882062069997912422165606" }, "id": "CVE-2024-41017-35605a2d", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7e21574195a45fc193555fa40e99fed16565ff7e" }, { "signature_version": "v1", "signature_type": "Line", "target": { "file": "fs/jfs/xattr.c" }, "deprecated": false, "digest": { "line_hashes": [ "308544276059562008642344751349671253058", "332889882221938267698944684769674649453", "323585934589071353542814791306068729493", "323293562209655894456809467673995358571", "97900349366480261157158558344841555081", "22523298367176732825474565255654489690", "119151116356278847791525370345103906774", "59119815036124814882066691536728043995", "26729843576558839132835022943968859600", "36243336417894233531793917648263485421", "193167999141198017891242991167834158472", "327133548672119411743190974297631847730", "151088234726763817957219904661878347967", "334955521348071046428878538888823398423", "70135975923178363094730363177488094702", "34488156798232700945607798128452488233", "141705826914729364372109159686684658664", "104482820914375734667426691630246889150", "292600880089204384931409969705264260612", "250942862949487023120284698504777499889", "141409178003407268252992673634988586452", "336797069635513997736757398274002959850" ], "threshold": 0.9 }, "id": "CVE-2024-41017-3ba8fe26", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@17440dbc66ab98b410514b04987f61deedb86751" }, { "signature_version": "v1", "signature_type": "Line", "target": { "file": "fs/jfs/xattr.c" }, "deprecated": false, "digest": { "line_hashes": [ "308544276059562008642344751349671253058", "332889882221938267698944684769674649453", "323585934589071353542814791306068729493", "323293562209655894456809467673995358571", "97900349366480261157158558344841555081", "22523298367176732825474565255654489690", "119151116356278847791525370345103906774", "59119815036124814882066691536728043995", "26729843576558839132835022943968859600", "36243336417894233531793917648263485421", "193167999141198017891242991167834158472", "327133548672119411743190974297631847730", "151088234726763817957219904661878347967", "334955521348071046428878538888823398423", "70135975923178363094730363177488094702", "34488156798232700945607798128452488233", "141705826914729364372109159686684658664", "104482820914375734667426691630246889150", "292600880089204384931409969705264260612", "250942862949487023120284698504777499889", "141409178003407268252992673634988586452", "336797069635513997736757398274002959850" ], "threshold": 0.9 }, "id": "CVE-2024-41017-444fac51", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dbde7bc91093fa9c2410e418b236b70fde044b73" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "fs/jfs/xattr.c", "function": "jfs_listxattr" }, "deprecated": false, "digest": { "length": 880.0, "function_hash": "112841498775573498117924276806373409502" }, "id": "CVE-2024-41017-4cff8852", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@17440dbc66ab98b410514b04987f61deedb86751" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "fs/jfs/xattr.c", "function": "jfs_listxattr" }, "deprecated": false, "digest": { "length": 880.0, "function_hash": "112841498775573498117924276806373409502" }, "id": "CVE-2024-41017-589147ea", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7e21574195a45fc193555fa40e99fed16565ff7e" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "fs/jfs/xattr.c", "function": "jfs_listxattr" }, "deprecated": false, "digest": { "length": 880.0, "function_hash": "112841498775573498117924276806373409502" }, "id": "CVE-2024-41017-61f2fa46", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4e034f7e563ab723b93a59980e4a1bb33198ece8" }, { "signature_version": "v1", "signature_type": "Line", "target": { "file": "fs/jfs/xattr.c" }, "deprecated": false, "digest": { "line_hashes": [ "308544276059562008642344751349671253058", "332889882221938267698944684769674649453", "323585934589071353542814791306068729493", "323293562209655894456809467673995358571", "97900349366480261157158558344841555081", "22523298367176732825474565255654489690", "119151116356278847791525370345103906774", "59119815036124814882066691536728043995", "26729843576558839132835022943968859600", "36243336417894233531793917648263485421", "193167999141198017891242991167834158472", "327133548672119411743190974297631847730", "151088234726763817957219904661878347967", "334955521348071046428878538888823398423", "70135975923178363094730363177488094702", "34488156798232700945607798128452488233", "141705826914729364372109159686684658664", "104482820914375734667426691630246889150", "292600880089204384931409969705264260612", "250942862949487023120284698504777499889", "141409178003407268252992673634988586452", "336797069635513997736757398274002959850" ], "threshold": 0.9 }, "id": "CVE-2024-41017-63a00bad", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7f91bd0f2941fa36449ce1a15faaa64f840d9746" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "fs/jfs/xattr.c", "function": "__jfs_getxattr" }, "deprecated": false, "digest": { "length": 924.0, "function_hash": "196754699848022882062069997912422165606" }, "id": "CVE-2024-41017-647e825c", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4e034f7e563ab723b93a59980e4a1bb33198ece8" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "fs/jfs/xattr.c", "function": "__jfs_getxattr" }, "deprecated": false, "digest": { "length": 924.0, "function_hash": "196754699848022882062069997912422165606" }, "id": "CVE-2024-41017-6add25fb", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dbde7bc91093fa9c2410e418b236b70fde044b73" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "fs/jfs/xattr.c", "function": "__jfs_getxattr" }, "deprecated": false, "digest": { "length": 924.0, "function_hash": "196754699848022882062069997912422165606" }, "id": "CVE-2024-41017-6cb8e47e", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7f91bd0f2941fa36449ce1a15faaa64f840d9746" }, { "signature_version": "v1", "signature_type": "Line", "target": { "file": "fs/jfs/xattr.c" }, "deprecated": false, "digest": { "line_hashes": [ "308544276059562008642344751349671253058", "332889882221938267698944684769674649453", "323585934589071353542814791306068729493", "323293562209655894456809467673995358571", "97900349366480261157158558344841555081", "22523298367176732825474565255654489690", "119151116356278847791525370345103906774", "59119815036124814882066691536728043995", "26729843576558839132835022943968859600", "36243336417894233531793917648263485421", "193167999141198017891242991167834158472", "327133548672119411743190974297631847730", "151088234726763817957219904661878347967", "334955521348071046428878538888823398423", "70135975923178363094730363177488094702", "34488156798232700945607798128452488233", "141705826914729364372109159686684658664", "104482820914375734667426691630246889150", "292600880089204384931409969705264260612", "250942862949487023120284698504777499889", "141409178003407268252992673634988586452", "336797069635513997736757398274002959850" ], "threshold": 0.9 }, "id": "CVE-2024-41017-748aefe8", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4e034f7e563ab723b93a59980e4a1bb33198ece8" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "fs/jfs/xattr.c", "function": "__jfs_getxattr" }, "deprecated": false, "digest": { "length": 924.0, "function_hash": "196754699848022882062069997912422165606" }, "id": "CVE-2024-41017-ebe66477", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@17440dbc66ab98b410514b04987f61deedb86751" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "fs/jfs/xattr.c", "function": "jfs_listxattr" }, "deprecated": false, "digest": { "length": 880.0, "function_hash": "112841498775573498117924276806373409502" }, "id": "CVE-2024-41017-fd20e0fa", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dbde7bc91093fa9c2410e418b236b70fde044b73" } ] }