cbcvebase.
CVE-2024-41077
published 2024-07-29

CVE-2024-41077: In the Linux kernel, the following vulnerability has been resolved: null_blk: fix validation of block size Block size should be between 512 and PAGE_SIZE and…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.2th percentile
In the Linux kernel, the following vulnerability has been resolved: null_blk: fix validation of block size Block size should be between 512 and PAGE_SIZE and be a power of 2. The current check does not validate this, so update the check. Without this patch, null_blk would Oops due to a null pointer deref when loaded with bs=1536 [1]. [axboe: remove unnecessary braces and != 0 check]

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= cedcafad8277b3a07e90bf2f68fff5c6b28a183e < 9625afe1dd4a158a14bb50f81af9e2dac634c0b19625afe1dd4a158a14bb50f81af9e2dac634c0b1
linuxlinux>= cedcafad8277b3a07e90bf2f68fff5c6b28a183e < 9b873bdaae64bddade9d8c6df23c8a31948d47d09b873bdaae64bddade9d8c6df23c8a31948d47d0
linuxlinux>= cedcafad8277b3a07e90bf2f68fff5c6b28a183e < 2772ed2fc075eef7df3789906fc9dae01e4e132e2772ed2fc075eef7df3789906fc9dae01e4e132e
linuxlinux>= cedcafad8277b3a07e90bf2f68fff5c6b28a183e < 08f03186b96e25e3154916a2e70732557c770ea708f03186b96e25e3154916a2e70732557c770ea7
linuxlinux>= cedcafad8277b3a07e90bf2f68fff5c6b28a183e < f92409a9da02f27d05d713bff5f865e386cef9b3f92409a9da02f27d05d713bff5f865e386cef9b3
linuxlinux>= cedcafad8277b3a07e90bf2f68fff5c6b28a183e < c462ecd659b5fce731f1d592285832fd6ad54053c462ecd659b5fce731f1d592285832fd6ad54053
linuxlinux_kernel< 5.10.2235.10.223
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.9.11-16.9.11-1
linuxlinux_kernel>= 0 < 6.9.11-16.9.11-1
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.11 < 5.15.1645.15.164
linuxlinux_kernel>= 5.16 < 6.1.1016.1.101
linuxlinux_kernel>= 6.2 < 6.6.426.6.42
linuxlinux_kernel>= 6.7 < 6.9.116.9.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.