cbcvebase.
CVE-2024-50272
published 2024-11-19

CVE-2024-50272: In the Linux kernel, the following vulnerability has been resolved: filemap: Fix bounds checking in filemap_read() If the caller supplies an iocb->ki_pos value…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved: filemap: Fix bounds checking in filemap_read() If the caller supplies an iocb->ki_pos value that is close to the filesystem upper limit, and an iterator with a count that causes us to overflow that limit, then filemap_read() enters an infinite loop. This behaviour was discovered when testing xfstests generic/525 with the "localio" optimisation for loopback NFS mounts.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.16.40 < 3.173.17
linuxlinux>= 4.7.10 < 4.84.8
linuxlinux>= 4.8.4 < 4.94.9
linuxlinux>= c2a9737f45e27d8263ff9643f994bda9bac0b944 < 6cc52df69e8464811f9f6fc12f7aaa78451eb0b86cc52df69e8464811f9f6fc12f7aaa78451eb0b8
linuxlinux>= c2a9737f45e27d8263ff9643f994bda9bac0b944 < 26530b757c81f1389fb33ae0357500150933161b26530b757c81f1389fb33ae0357500150933161b
linuxlinux>= c2a9737f45e27d8263ff9643f994bda9bac0b944 < a2746ab3bbc9c6408da5cd072653ec8c24749235a2746ab3bbc9c6408da5cd072653ec8c24749235
linuxlinux>= c2a9737f45e27d8263ff9643f994bda9bac0b944 < 6450e73f4c86d481ac2e22e1bc848d346e1408266450e73f4c86d481ac2e22e1bc848d346e140826
linuxlinux>= c2a9737f45e27d8263ff9643f994bda9bac0b944 < ace149e0830c380ddfce7e466fe860ca502fe4eeace149e0830c380ddfce7e466fe860ca502fe4ee
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 3.16.40 < 3.173.17
linuxlinux_kernel>= 4.7.10 < 4.84.8
linuxlinux_kernel>= 4.8.4 < 4.94.9
linuxlinux_kernel>= 4.9 < 6.1.1176.1.117

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.