CVE-2024-41016

In the Linux kernel, the following vulnerability has been resolved: ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry() xattr in ocfs2 maybe 'non-indexed', which saved with additional space requested. It's better to check if the memory is out of bound before memcmp, although this possibility mainly comes from crafted poisonous images.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

07 Oct 2025, 19:24

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/57a3d89831fcaa2cdbe024b47c7c36d5a56c3637 - () https://git.kernel.org/stable/c/57a3d89831fcaa2cdbe024b47c7c36d5a56c3637 - Patch
References () https://git.kernel.org/stable/c/af77c4fc1871847b528d58b7fdafb4aa1f6a9262 - () https://git.kernel.org/stable/c/af77c4fc1871847b528d58b7fdafb4aa1f6a9262 - Patch
References () https://git.kernel.org/stable/c/c031d286eceb82f72f8623b7f4abd2aa491bfb5e - () https://git.kernel.org/stable/c/c031d286eceb82f72f8623b7f4abd2aa491bfb5e - Patch
References () https://git.kernel.org/stable/c/c726dea9d0c806d64c26fcef483b1fb9474d8c5e - () https://git.kernel.org/stable/c/c726dea9d0c806d64c26fcef483b1fb9474d8c5e - Patch
References () https://git.kernel.org/stable/c/cfb926051fab19b10d1e65976211f364aa820180 - () https://git.kernel.org/stable/c/cfb926051fab19b10d1e65976211f364aa820180 - Patch
References () https://git.kernel.org/stable/c/e2b3d7a9d019d4d1a0da6c3ea64a1ff79c99c090 - () https://git.kernel.org/stable/c/e2b3d7a9d019d4d1a0da6c3ea64a1ff79c99c090 - Patch
References () https://git.kernel.org/stable/c/e4ffea01adf3323c821b6f37e9577d2d400adbaa - () https://git.kernel.org/stable/c/e4ffea01adf3323c821b6f37e9577d2d400adbaa - Patch
References () https://git.kernel.org/stable/c/e8f9c4af7af7e9e4cd09c0251c7936593147419f - () https://git.kernel.org/stable/c/e8f9c4af7af7e9e4cd09c0251c7936593147419f - Patch

21 Nov 2024, 09:32

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/af77c4fc1871847b528d58b7fdafb4aa1f6a9262 - () https://git.kernel.org/stable/c/af77c4fc1871847b528d58b7fdafb4aa1f6a9262 -

08 Nov 2024, 16:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/e2b3d7a9d019d4d1a0da6c3ea64a1ff79c99c090 -
  • () https://git.kernel.org/stable/c/e8f9c4af7af7e9e4cd09c0251c7936593147419f -

17 Oct 2024, 14:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/57a3d89831fcaa2cdbe024b47c7c36d5a56c3637 -
  • () https://git.kernel.org/stable/c/c031d286eceb82f72f8623b7f4abd2aa491bfb5e -

30 Sep 2024, 15:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/c726dea9d0c806d64c26fcef483b1fb9474d8c5e -
  • () https://git.kernel.org/stable/c/cfb926051fab19b10d1e65976211f364aa820180 -
  • () https://git.kernel.org/stable/c/e4ffea01adf3323c821b6f37e9577d2d400adbaa -

29 Jul 2024, 14:12

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: ocfs2: verificación de límite estricto antes de memcmp en ocfs2_xattr_find_entry() xattr en ocfs2 puede ser 'non-indexed', lo que se guardó con espacio adicional solicitado. Es mejor comprobar si la memoria está fuera de los límites antes de memcmp, aunque esta posibilidad proviene principalmente de imágenes venenosas creadas.

29 Jul 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-29 07:15

Updated : 2025-10-07 19:24


NVD link : CVE-2024-41016

Mitre link : CVE-2024-41016

CVE.ORG link : CVE-2024-41016


JSON object : View

Products Affected

linux

  • linux_kernel