We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-26736

afs: Increase buffer size in afs_update_volume_status()



Description

In the Linux kernel, the following vulnerability has been resolved: afs: Increase buffer size in afs_update_volume_status() The max length of volume->vid value is 20 characters. So increase idbuf[] size up to 24 to avoid overflow. Found by Linux Verification Center (linuxtesting.org) with SVACE. [DH: Actually, it's 20 + NUL, so increase it to 24 and use snprintf()]

Reserved 2024-02-19 | Published 2024-04-03 | Updated 2024-12-19 | Assigner Linux

Product status

Default status
unaffected

d2ddc776a4581d900fc3bdc7803b403daae64d88 before 5c27d85a69fa16a08813ba37ddfb4bbc9a1ed6b5
affected

d2ddc776a4581d900fc3bdc7803b403daae64d88 before d9b5e2b7a8196850383c70d099bfd39e81ab6637
affected

d2ddc776a4581d900fc3bdc7803b403daae64d88 before e56662160fc24d28cb75ac095cc6415ae1bda43e
affected

d2ddc776a4581d900fc3bdc7803b403daae64d88 before e8530b170e464017203e3b8c6c49af6e916aece1
affected

d2ddc776a4581d900fc3bdc7803b403daae64d88 before 6e6065dd25b661420fac19c34282b6c626fcd35e
affected

d2ddc776a4581d900fc3bdc7803b403daae64d88 before d34a5e57632bb5ff825196ddd9a48ca403626dfa
affected

d2ddc776a4581d900fc3bdc7803b403daae64d88 before 6ea38e2aeb72349cad50e38899b0ba6fbcb2af3d
affected

Default status
affected

4.15
affected

Any version before 4.15
unaffected

5.4.270
unaffected

5.10.211
unaffected

5.15.150
unaffected

6.1.80
unaffected

6.6.19
unaffected

6.7.7
unaffected

6.8
unaffected

References

git.kernel.org/...c/5c27d85a69fa16a08813ba37ddfb4bbc9a1ed6b5

git.kernel.org/...c/d9b5e2b7a8196850383c70d099bfd39e81ab6637

git.kernel.org/...c/e56662160fc24d28cb75ac095cc6415ae1bda43e

git.kernel.org/...c/e8530b170e464017203e3b8c6c49af6e916aece1

git.kernel.org/...c/6e6065dd25b661420fac19c34282b6c626fcd35e

git.kernel.org/...c/d34a5e57632bb5ff825196ddd9a48ca403626dfa

git.kernel.org/...c/6ea38e2aeb72349cad50e38899b0ba6fbcb2af3d

cve.org (CVE-2024-26736)

nvd.nist.gov (CVE-2024-26736)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-26736

Support options

Helpdesk Chat, Email, Knowledgebase