THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-26736

afs: Increase buffer size in afs_update_volume_status()

AssignerLinux
Reserved2024-02-19
Published2024-04-03
Updated2024-06-04

Description

In the Linux kernel, the following vulnerability has been resolved: afs: Increase buffer size in afs_update_volume_status() The max length of volume->vid value is 20 characters. So increase idbuf[] size up to 24 to avoid overflow. Found by Linux Verification Center (linuxtesting.org) with SVACE. [DH: Actually, it's 20 + NUL, so increase it to 24 and use snprintf()]

Product status

Default status
unaffected

d2ddc776a458 before 5c27d85a69fa
affected

d2ddc776a458 before d9b5e2b7a819
affected

d2ddc776a458 before e56662160fc2
affected

d2ddc776a458 before e8530b170e46
affected

d2ddc776a458 before 6e6065dd25b6
affected

d2ddc776a458 before d34a5e57632b
affected

d2ddc776a458 before 6ea38e2aeb72
affected

Default status
affected

4.15
affected

Any version before 4.15
unaffected

5.4.270
unaffected

5.10.211
unaffected

5.15.150
unaffected

6.1.80
unaffected

6.6.19
unaffected

6.7.7
unaffected

6.8
unaffected

References

https://git.kernel.org/stable/c/5c27d85a69fa16a08813ba37ddfb4bbc9a1ed6b5

https://git.kernel.org/stable/c/d9b5e2b7a8196850383c70d099bfd39e81ab6637

https://git.kernel.org/stable/c/e56662160fc24d28cb75ac095cc6415ae1bda43e

https://git.kernel.org/stable/c/e8530b170e464017203e3b8c6c49af6e916aece1

https://git.kernel.org/stable/c/6e6065dd25b661420fac19c34282b6c626fcd35e

https://git.kernel.org/stable/c/d34a5e57632bb5ff825196ddd9a48ca403626dfa

https://git.kernel.org/stable/c/6ea38e2aeb72349cad50e38899b0ba6fbcb2af3d

cve.org CVE-2024-26736

nvd.nist.gov CVE-2024-26736

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-26736
© Copyright 2024 THREATINT. Made in Cyprus with +