CVE-2024-41019

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate ff offset This adds sanity checks for ff offset. There is a check on rt->first_free at first, but walking through by ff without any check. If the second ff is a large offset. We may encounter an out-of-bound read.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

07 Oct 2025, 19:30

Type Values Removed Values Added
CWE CWE-125
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/35652dfa8cc9a8a900ec0f1e0395781f94ffc5f0 - () https://git.kernel.org/stable/c/35652dfa8cc9a8a900ec0f1e0395781f94ffc5f0 - Patch
References () https://git.kernel.org/stable/c/50c47879650b4c97836a0086632b3a2e300b0f06 - () https://git.kernel.org/stable/c/50c47879650b4c97836a0086632b3a2e300b0f06 - Patch
References () https://git.kernel.org/stable/c/617cf144c206f98978ec730b17159344fd147cb4 - () https://git.kernel.org/stable/c/617cf144c206f98978ec730b17159344fd147cb4 - Patch
References () https://git.kernel.org/stable/c/6ae7265a7b816879fd0203e83b5030d3720bbb7a - () https://git.kernel.org/stable/c/6ae7265a7b816879fd0203e83b5030d3720bbb7a - Patch
References () https://git.kernel.org/stable/c/818a257428644b8873e79c44404d8fb6598d4440 - () https://git.kernel.org/stable/c/818a257428644b8873e79c44404d8fb6598d4440 - Patch
References () https://git.kernel.org/stable/c/82c94e6a7bd116724738aa67eba6f5fedf3a3319 - () https://git.kernel.org/stable/c/82c94e6a7bd116724738aa67eba6f5fedf3a3319 - Patch
First Time Linux linux Kernel
Linux

21 Nov 2024, 09:32

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/35652dfa8cc9a8a900ec0f1e0395781f94ffc5f0 - () https://git.kernel.org/stable/c/35652dfa8cc9a8a900ec0f1e0395781f94ffc5f0 -
References () https://git.kernel.org/stable/c/50c47879650b4c97836a0086632b3a2e300b0f06 - () https://git.kernel.org/stable/c/50c47879650b4c97836a0086632b3a2e300b0f06 -
References () https://git.kernel.org/stable/c/617cf144c206f98978ec730b17159344fd147cb4 - () https://git.kernel.org/stable/c/617cf144c206f98978ec730b17159344fd147cb4 -
References () https://git.kernel.org/stable/c/6ae7265a7b816879fd0203e83b5030d3720bbb7a - () https://git.kernel.org/stable/c/6ae7265a7b816879fd0203e83b5030d3720bbb7a -
References () https://git.kernel.org/stable/c/818a257428644b8873e79c44404d8fb6598d4440 - () https://git.kernel.org/stable/c/818a257428644b8873e79c44404d8fb6598d4440 -
References () https://git.kernel.org/stable/c/82c94e6a7bd116724738aa67eba6f5fedf3a3319 - () https://git.kernel.org/stable/c/82c94e6a7bd116724738aa67eba6f5fedf3a3319 -

29 Jul 2024, 14:12

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: fs/ntfs3: Validar ff offset Esto agrega comprobaciones de sanitización para ff offset. Al principio hay una verificación en rt->first_free, pero pasa por ff sin ninguna verificación. Si el segundo ff es un desplazamiento grande. Es posible que nos encontremos con una lectura fuera de los límites.

29 Jul 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-29 07:15

Updated : 2025-10-07 19:30


NVD link : CVE-2024-41019

Mitre link : CVE-2024-41019

CVE.ORG link : CVE-2024-41019


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-125

Out-of-bounds Read