cbcvebase.
CVE-2024-56598
published 2024-12-27

CVE-2024-56598: In the Linux kernel, the following vulnerability has been resolved: jfs: array-index-out-of-bounds fix in dtReadFirst The value of stbl can be sometimes out of…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: jfs: array-index-out-of-bounds fix in dtReadFirst The value of stbl can be sometimes out of bounds due to a bad filesystem. Added a check with appopriate return of error code in that case.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 25f1e673ef61d6bf9a6022e27936785896d7494825f1e673ef61d6bf9a6022e27936785896d74948
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8c97a4d5463a1c972ef576ac499ea9b05f9560978c97a4d5463a1c972ef576ac499ea9b05f956097
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 823d573f5450ca6be80b36f54d1902ac7cd23fb9823d573f5450ca6be80b36f54d1902ac7cd23fb9
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2eea5fda5556ef03defebf07b0a12fcd2c5210f42eea5fda5556ef03defebf07b0a12fcd2c5210f4
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fd993b2180b4c373af8b99aa28d4dcda5c2a8f10fd993b2180b4c373af8b99aa28d4dcda5c2a8f10
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 22dcbf7661c6ffc3247978c254dc40b833a0d42922dcbf7661c6ffc3247978c254dc40b833a0d429
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ca84a2c9be482836b86d780244f0357e5a778c46ca84a2c9be482836b86d780244f0357e5a778c46
linuxlinux_kernel< 5.4.2875.4.287
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-57.596.8.0-57.59
linuxlinux_kernel>= 0 < 3.13.0-206.2573.13.0-206.257
linuxlinux_kernel>= 0 < 4.4.0-278.3124.4.0-278.312
linuxlinux_kernel>= 0 < 4.4.0-268.3024.4.0-268.302
linuxlinux_kernel>= 0 < 4.15.0-247.2594.15.0-247.259
linuxlinux_kernel>= 0 < 4.15.0-237.2494.15.0-237.249
linuxlinux_kernel>= 0 < 5.4.0-218.2385.4.0-218.238
linuxlinux_kernel>= 0 < 5.15.0-141.1515.15.0-141.151

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.