cbcvebase.
CVE-2024-57850
published 2025-01-11

CVE-2024-57850: In the Linux kernel, the following vulnerability has been resolved: jffs2: Prevent rtime decompress memory corruption The rtime decompression routine does not…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.9th percentile
In the Linux kernel, the following vulnerability has been resolved: jffs2: Prevent rtime decompress memory corruption The rtime decompression routine does not fully check bounds during the entirety of the decompression pass and can corrupt memory outside the decompression buffer if the compressed data is corrupted. This adds the required check to prevent this failure mode.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 421f9e9f0fae9f8e721ffa07f22d9765fa1214d5421f9e9f0fae9f8e721ffa07f22d9765fa1214d5
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f6fc251baefc3cdc4f41f2f5a47940d7d4a67332f6fc251baefc3cdc4f41f2f5a47940d7d4a67332
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < bd384b04ad1995441b18fe6c1366d02de8c5d5ebbd384b04ad1995441b18fe6c1366d02de8c5d5eb
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 47c9a7f81027a78afea9d2e9a54bfd8fabb6b3d047c9a7f81027a78afea9d2e9a54bfd8fabb6b3d0
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6808a1812a3419542223e7fe9e2de577e99e45d16808a1812a3419542223e7fe9e2de577e99e45d1
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < dc39b08fcc3831b0bc46add91ba93cd2aab50716dc39b08fcc3831b0bc46add91ba93cd2aab50716
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fe051552f5078fa02d593847529a3884305a6ffefe051552f5078fa02d593847529a3884305a6ffe
linuxlinux_kernel< 5.4.2875.4.287
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 3.13.0-210.2613.13.0-210.261
linuxlinux_kernel>= 0 < 4.4.0-269.3034.4.0-269.303
linuxlinux_kernel>= 0 < 4.15.0-238.2504.15.0-238.250
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231
linuxlinux_kernel>= 6.2 < 6.6.666.6.66

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.