CVE-2024-41018

Source
https://cve.org/CVERecord?id=CVE-2024-41018
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-41018.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-41018
Downstream
BELL (1)
DEBIAN (1)
MGASA (2)
OESA (1)
UBUNTU (1)
Published
2024-07-29T06:37:04Z
Modified
2026-10-08T02:48:33Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
fs/ntfs3: Add a check for attr_names and oatbl
Details

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: Add a check for attr_names and oatbl

Added out-of-bound checking for *ane (ATTR_NAME_ENTRY).

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41018.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e0b64e4ad2eb013fd3299e34e7fe5e19f321e140
Fixed
f3124d51e4e7b56a732419d8dc270e807252334f
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
865e7a7700d930d34895a70f8af2eb4e778a5b0e
Fixed
c114d2b88f8b226d4b2acf5a1ba0412cde6c31dd
Fixed
9b71f820f7168f1eab8378c80c7ea8a022a475bc
Fixed
702d4930eb06dcfda85a2fa67e8a1a27bfa2a845
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6.6.19
Fixed
6.6.43
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6.7.7
Fixed
6.8
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
653687cca0fdbf426c078b46c377c57bee49e837

Affected versions

v6.*
v6.6.19
v6.6.20
v6.6.21
v6.6.22
v6.6.23
v6.6.24
v6.6.25
v6.6.26
v6.6.27
v6.6.28
v6.6.29
v6.6.30
v6.6.31
v6.6.32
v6.6.33
v6.6.34
v6.6.35
v6.6.36
v6.6.37
v6.6.38
v6.6.39
v6.6.40
v6.6.41
v6.6.42
v6.7.10
v6.7.11
v6.7.12
v6.7.7
v6.7.8
v6.7.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-41018.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.6.43
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.9.12
Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.10.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-41018.json"