cbcvebase.
CVE-2024-49996
published 2024-10-21

CVE-2024-49996: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix buffer overflow when parsing NFS reparse points ReparseDataLength is sum of the…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.33%
25.5th percentile
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix buffer overflow when parsing NFS reparse points ReparseDataLength is sum of the InodeType size and DataBuffer size. So to get DataBuffer size it is needed to subtract InodeType's size from ReparseDataLength. Function cifs_strndup_from_utf16() is currentlly accessing buf->DataBuffer at position after the end of the buffer because it does not subtract InodeType size from the length. Fix this problem and correctly subtract variable len. Member InodeType is present only when reparse buffer is large enough. Check for ReparseDataLength before accessing InodeType to prevent another invalid memory access. Major and minor rdev values are present also only when reparse buffer is large enough. Check for reparse buffer size before calling reparse_mkdev().

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= d5ecebc4900df7f6e8dff0717574668885110553 < 7b222d6cb87077faf56a687a72af1951cf78c8a97b222d6cb87077faf56a687a72af1951cf78c8a9
linuxlinux>= d5ecebc4900df7f6e8dff0717574668885110553 < 73b078e3314d4854fd8286f3ba65c860ddd3a3dd73b078e3314d4854fd8286f3ba65c860ddd3a3dd
linuxlinux>= d5ecebc4900df7f6e8dff0717574668885110553 < 01cdddde39b065074fd48f07027757783cbf5b7d01cdddde39b065074fd48f07027757783cbf5b7d
linuxlinux>= d5ecebc4900df7f6e8dff0717574668885110553 < ec79e6170bcae8a6036a4b6960f5e7e59a785601ec79e6170bcae8a6036a4b6960f5e7e59a785601
linuxlinux>= d5ecebc4900df7f6e8dff0717574668885110553 < c6db81c550cea0c73bd72ef55f579991e0e4ba07c6db81c550cea0c73bd72ef55f579991e0e4ba07
linuxlinux>= d5ecebc4900df7f6e8dff0717574668885110553 < 803b3a39cb096d8718c0aebc03fd19f11c7dc919803b3a39cb096d8718c0aebc03fd19f11c7dc919
linuxlinux>= d5ecebc4900df7f6e8dff0717574668885110553 < c173d47b69f07cd7ca08efb4e458adbd4725d8e9c173d47b69f07cd7ca08efb4e458adbd4725d8e9
linuxlinux>= d5ecebc4900df7f6e8dff0717574668885110553 < e2a8910af01653c1c268984855629d71fb81f404e2a8910af01653c1c268984855629d71fb81f404
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.3 < 5.4.2875.4.287
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231
linuxlinux_kernel>= 6.11 < 6.11.36.11.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.