cbcvebase.
CVE-2024-26981
published 2024-05-01

CVE-2024-26981: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix OOB in nilfs_set_de_type The size of the nilfs_type_by_mode array in the…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.2th percentile
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix OOB in nilfs_set_de_type The size of the nilfs_type_by_mode array in the fs/nilfs2/dir.c file is defined as "S_IFMT >> S_SHIFT", but the nilfs_set_de_type() function, which uses this array, specifies the index to read from the array in the same way as "(mode & S_IFMT) >> S_SHIFT". static void nilfs_set_de_type(struct nilfs_dir_entry *de, struct inode *inode) { umode_t mode = inode->i_mode; de->file_type = nilfs_type_by_mode[(mode & S_IFMT)>>S_SHIFT]; // oob } However, when the index is determined this way, an out-of-bounds (OOB) error occurs by referring to an index that is 1 larger than the array size when the condition "mode & S_IFMT == S_IFMT" is satisfied. Therefore, a patch to resize the nilfs_type_by_mode array should be applied to prevent OOB errors.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < 054f29e9ca05be3906544c5f2a2c7321c30a4243054f29e9ca05be3906544c5f2a2c7321c30a4243
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < 90f43980ea6be4ad903e389be9a27a2a0018f1c890f43980ea6be4ad903e389be9a27a2a0018f1c8
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < 7061c7efbb9e8f11ce92d6b4646405ea2b0b4de17061c7efbb9e8f11ce92d6b4646405ea2b0b4de1
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < bdbe483da21f852c93b22557b146bc4d989260f0bdbe483da21f852c93b22557b146bc4d989260f0
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < 897ac5306bbeb83e90c437326f7044c79a17c611897ac5306bbeb83e90c437326f7044c79a17c611
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < 2382eae66b196c31893984a538908c3eb7506ff92382eae66b196c31893984a538908c3eb7506ff9
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < 90823f8d9ecca3d5fa6b102c8e464c62f416975f90823f8d9ecca3d5fa6b102c8e464c62f416975f
linuxlinux>= 2ba466d74ed74f073257f86e61519cb8f8f46184 < c4a7dc9523b59b3e73fd522c73e95e072f876b16c4a7dc9523b59b3e73fd522c73e95e072f876b16
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 2.6.30 < 4.19.3134.19.313
linuxlinux_kernel>= 4.20 < 5.4.2755.4.275
linuxlinux_kernel>= 5.11 < 5.15.1575.15.157
linuxlinux_kernel>= 5.16 < 6.1.886.1.88
linuxlinux_kernel>= 5.5 < 5.10.2165.10.216
linuxlinux_kernel>= 6.2 < 6.6.296.6.29

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.