cbcvebase.
CVE-2024-53147
published 2024-12-24

CVE-2024-53147: In the Linux kernel, the following vulnerability has been resolved: exfat: fix out-of-bounds access of directory entries In the case of the directory size is…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.21%
11.0th percentile
In the Linux kernel, the following vulnerability has been resolved: exfat: fix out-of-bounds access of directory entries In the case of the directory size is greater than or equal to the cluster size, if start_clu becomes an EOF cluster(an invalid cluster) due to file system corruption, then the directory entry where ei->hint_femp.eidx hint is outside the directory, resulting in an out-of-bounds access, which may cause further file system corruption. This commit adds a check for start_clu, if it is an invalid cluster, the file or directory will be treated as empty.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.3-1 (forky)linux 6.12.3-1 (forky)
linuxlinux
linuxlinux>= 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 < a0120d6463368378539ef928cf067d02372efb8ca0120d6463368378539ef928cf067d02372efb8c
linuxlinux>= 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 < 3ddd1cb2b458ff6a193bc845f408dfff217db29e3ddd1cb2b458ff6a193bc845f408dfff217db29e
linuxlinux>= 1acf1a564b6034b5af1e7fb23cb98cb3bb4f6003 < 184fa506e392eb78364d9283c961217ff2c0617b184fa506e392eb78364d9283c961217ff2c0617b
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.7 < 6.11.116.11.11
linuxlinux_kernel>= 6.12 < 6.12.26.12.2
msrcazl3_kernel_6.6.96.2-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_msrc4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.