CVE-2024-41017
HIGH severity · CVSS 7.8
7.8CVSS HIGH
Summary
In the Linux kernel, the following vulnerability has been resolved: jfs: don't walk off the end of ealist Add a check before visiting the members of ea to make sure each ea stays within the ealist.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)0%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: https://git.kernel.org/stable/c/17440dbc66ab98b410514b04987f61deedb86751 ↗
Additional information
- NVD record
- https://git.kernel.org/stable/c/17440dbc66ab98b410514b04987f61deedb86751Patch
- https://git.kernel.org/stable/c/4e034f7e563ab723b93a59980e4a1bb33198ece8Patch
- https://git.kernel.org/stable/c/6386f1b6a10e5d1ddd03db4ff6dfc55d488852cePatch
- https://git.kernel.org/stable/c/7e21574195a45fc193555fa40e99fed16565ff7ePatch
- https://git.kernel.org/stable/c/7f91bd0f2941fa36449ce1a15faaa64f840d9746Patch
- https://git.kernel.org/stable/c/d0fa70aca54c8643248e89061da23752506ec0d4Patch
- https://git.kernel.org/stable/c/dbde7bc91093fa9c2410e418b236b70fde044b73Patch
- https://git.kernel.org/stable/c/f4435f476b9bf059cd9e26a69f5b29c768d00375Patch