Description In the Linux kernel, the following vulnerability has been resolved:
orangefs: fix a oob in orangefs_debug_write
I got a syzbot report: slab-out-of-bounds Read in
orangefs_debug_write... several people suggested fixes,
I tested Al Viro's suggestion and made this patch.
CVSS vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Exploitability: 1.8 | Impact: 5.2 Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: High
Affected Packages9 packages Show 4 more packages
🔴 Vulnerability Details41 OSV linux-azure, linux-azure-6.8, linux-azure-nvidia vulnerabilities ↗ 2025-09-03 ▶ OSV linux-gke, linux-hwe-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-raspi vulnerabilities ↗ 2025-08-28 ▶ OSV linux-raspi-realtime vulnerabilities ↗ 2025-08-26 ▶ OSV linux-oracle, linux-oracle-6.8 vulnerabilities ↗ 2025-08-21 ▶ OSV linux-aws-6.8, linux-gcp, linux-gcp-6.8, linux-gkeop, linux-ibm, linux-ibm-6.8 vulnerabilities ↗ 2025-08-20 ▶ Show 36 more
📋 Vendor Advisories42 Ubuntu Linux kernel (Azure) vulnerabilities ↗ 2025-09-03 ▶ Ubuntu Linux kernel vulnerabilities ↗ 2025-08-28 ▶ Ubuntu Linux kernel (Raspberry Pi Real-time) vulnerabilities ↗ 2025-08-26 ▶ Ubuntu Linux kernel (Oracle) vulnerabilities ↗ 2025-08-21 ▶ Ubuntu Linux kernel vulnerabilities ↗ 2025-08-20 ▶ Show 37 more