SB20250117124 - Integer underflow in Linux kernel nilfs2
Published: January 17, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer underflow (CVE-ID: CVE-2024-53690)
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to integer underflow within the nilfs_lookup() function in fs/nilfs2/namei.c, within the nilfs_iget() function in fs/nilfs2/inode.c. A local user can execute arbitrary code.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/284760b320a0bac411b18108316939707dccb12b
- https://git.kernel.org/stable/c/55e4baa0d32f0530ddc64c26620e1f2f8fa2724c
- https://git.kernel.org/stable/c/5d4ed71327b0b5f3b179a19dc3c06be9509ab3db
- https://git.kernel.org/stable/c/901ce9705fbb9f330ff1f19600e5daf9770b0175
- https://git.kernel.org/stable/c/912188316a8c9e41b8c1603c2276a05043b14f96
- https://git.kernel.org/stable/c/ef942d233643777f7b2a5deef620e82942983143
- https://git.kernel.org/stable/c/ff561987ff12b6a3233431ff659b5d332e22f153
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.7