UBUNTU-CVE-2024-41016
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-41016
UBUNTU-CVE-2024-41016
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry() xattr in ocfs2 maybe 'non-indexed', which saved with additional space requested. It's better to check if the memory is out of bound before memcmp, although this possibility mainly comes from crafted poisonous images.
References: https://ubuntu.com/security/CVE-2024-41016, https://www.cve.org/CVERecord?id=CVE-2024-41016, https://git.kernel.org/linus/af77c4fc1871847b528d58b7fdafb4aa1f6a9262, https://git.kernel.org/stable/c/af77c4fc1871847b528d58b7fdafb4aa1f6a9262, https://ubuntu.com/security/notices/USN-7166-1, https://ubuntu.com/security/notices/USN-7166-2, https://ubuntu.com/security/notices/USN-7166-3, https://ubuntu.com/security/notices/USN-7186-1, https://ubuntu.com/security/notices/USN-7186-2, https://ubuntu.com/security/notices/USN-7194-1, https://ubuntu.com/security/notices/USN-7166-4, https://ubuntu.com/security/notices/USN-7293-1, https://ubuntu.com/security/notices/USN-7294-1, https://ubuntu.com/security/notices/USN-7295-1, https://ubuntu.com/security/notices/USN-7301-1, https://ubuntu.com/security/notices/USN-7303-1, https://ubuntu.com/security/notices/USN-7304-1, https://ubuntu.com/security/notices/USN-7294-2, https://ubuntu.com/security/notices/USN-7294-3, https://ubuntu.com/security/notices/USN-7303-2, https://ubuntu.com/security/notices/USN-7311-1, https://ubuntu.com/security/notices/USN-7303-3, https://ubuntu.com/security/notices/USN-7294-4, https://ubuntu.com/security/notices/USN-7384-1, https://ubuntu.com/security/notices/USN-7385-1, https://ubuntu.com/security/notices/USN-7386-1, https://ubuntu.com/security/notices/USN-7393-1, https://ubuntu.com/security/notices/USN-7384-2, https://ubuntu.com/security/notices/USN-7401-1, https://ubuntu.com/security/notices/USN-7403-1, https://ubuntu.com/security/notices/USN-7413-1, https://ubuntu.com/security/notices/USN-7468-1, https://ubuntu.com/security/notices/USN-7539-1, https://ubuntu.com/security/notices/USN-7540-1
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
