SB2025021275 - Buffer overflow in Linux kernel fs
Published: February 12, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2024-57952)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the simple_offset_destroy(), offset_dir_open(), offset_dir_llseek(), offset_dir_emit() and offset_iterate_dir() functions in fs/libfs.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3f250b82040a72b0059ae00855a74d8570ad2147
- https://git.kernel.org/stable/c/9e9e710f68bac49bd9b587823c077d06363440e0
- https://git.kernel.org/stable/c/b662d858131da9a8a14e68661656989b14dbf113
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.1
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14