cbcvebase.
CVE-2024-56595
published 2024-12-27

CVE-2024-56595: In the Linux kernel, the following vulnerability has been resolved: jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree When the value of lp is…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.7th percentile
In the Linux kernel, the following vulnerability has been resolved: jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree When the value of lp is 0 at the beginning of the for loop, it will become negative in the next assignment and we should bail out.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b15000bcbecf27e0f7c0f149a409e5b865e28ca2b15000bcbecf27e0f7c0f149a409e5b865e28ca2
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 368a533152220b0a6f1142327d96c6b6361f3002368a533152220b0a6f1142327d96c6b6361f3002
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a3d408870bc19b794646871bc4c3a5daa66f91c5a3d408870bc19b794646871bc4c3a5daa66f91c5
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 491487eeddccc4bb49f2e59d8c8f35bec89c15ca491487eeddccc4bb49f2e59d8c8f35bec89c15ca
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3b5d21b56c3774bc84eab0a93aaac22a4475e2c43b5d21b56c3774bc84eab0a93aaac22a4475e2c4
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8a4311bbde702362fe7412045d06ab6767235dac8a4311bbde702362fe7412045d06ab6767235dac
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a174706ba4dad895c40b1d2277bade16dfacdcd9a174706ba4dad895c40b1d2277bade16dfacdcd9
linuxlinux_kernel< 5.4.2875.4.287
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-57.596.8.0-57.59
linuxlinux_kernel>= 0 < 3.13.0-205.2563.13.0-205.256
linuxlinux_kernel>= 0 < 4.4.0-278.3124.4.0-278.312
linuxlinux_kernel>= 0 < 4.4.0-267.3014.4.0-267.301
linuxlinux_kernel>= 0 < 4.15.0-237.2494.15.0-237.249
linuxlinux_kernel>= 0 < 4.15.0-247.2594.15.0-247.259
linuxlinux_kernel>= 0 < 4.15.0-236.2484.15.0-236.248
linuxlinux_kernel>= 0 < 5.4.0-212.2325.4.0-212.232

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.