cbcvebase.
CVE-2024-49902
published 2024-10-21

CVE-2024-49902: In the Linux kernel, the following vulnerability has been resolved: jfs: check if leafidx greater than num leaves per dmap tree syzbot report a out of bounds…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
20.9th percentile
In the Linux kernel, the following vulnerability has been resolved: jfs: check if leafidx greater than num leaves per dmap tree syzbot report a out of bounds in dbSplit, it because dmt_leafidx greater than num leaves per dmap tree, add a checking for dmt_leafidx in dbFindLeaf. Shaggy: Modified sanity check to apply to control pages as well as leaf pages.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d76b9a4c283c7535ae7c7c9b14984e75402951e1d76b9a4c283c7535ae7c7c9b14984e75402951e1
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 35b91f15f44ce3c01eba058ccb864bb04743e79235b91f15f44ce3c01eba058ccb864bb04743e792
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2451e5917c56be45d4add786e2a059dd9c2c37c42451e5917c56be45d4add786e2a059dd9c2c37c4
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 25d2a3ff02f22e215ce53355619df10cc5faa7ab25d2a3ff02f22e215ce53355619df10cc5faa7ab
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 058aa89b3318be3d66a103ba7c68d717561e1dc6058aa89b3318be3d66a103ba7c68d717561e1dc6
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7fff9a9f866e99931cf6fa260288e55d016265827fff9a9f866e99931cf6fa260288e55d01626582
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cb0eb10558802764f07de1dc439c4609e27cb4f0cb0eb10558802764f07de1dc439c4609e27cb4f0
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4a7bf6a01fb441009a6698179a739957efd88e384a7bf6a01fb441009a6698179a739957efd88e38
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d64ff0d2306713ff084d4b09f84ed1a8c75ecc32d64ff0d2306713ff084d4b09f84ed1a8c75ecc32
linuxlinux_kernel< 5.10.2275.10.227
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 0 < 4.4.0-266.3004.4.0-266.300
linuxlinux_kernel>= 0 < 4.15.0-235.2474.15.0-235.247
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.