UBUNTU-CVE-2024-47670
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-47670
UBUNTU-CVE-2024-47670
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: ocfs2: add bounds checking to ocfs2_xattr_find_entry() Add a paranoia check to make sure it doesn't stray beyond valid memory region containing ocfs2 xattr entries when scanning for a match. It will prevent out-of-bound access in case of crafted images.
References: https://ubuntu.com/security/CVE-2024-47670, https://www.cve.org/CVERecord?id=CVE-2024-47670, https://git.kernel.org/stable/c/9b32539590a8e6400ac2f6e7cf9cbb8e08711a2f, https://git.kernel.org/stable/c/1f6e167d6753fe3ea493cdc7f7de8d03147a4d39, https://git.kernel.org/stable/c/8e7bef408261746c160853fc27df3139659f5f77, https://git.kernel.org/stable/c/9e3041fecdc8f78a5900c3aa51d3d756e73264d6, https://ubuntu.com/security/notices/USN-7166-1, https://ubuntu.com/security/notices/USN-7166-2, https://ubuntu.com/security/notices/USN-7166-3, https://ubuntu.com/security/notices/USN-7186-1, https://ubuntu.com/security/notices/USN-7186-2, https://ubuntu.com/security/notices/USN-7194-1, https://ubuntu.com/security/notices/USN-7166-4, https://ubuntu.com/security/notices/USN-7293-1, https://ubuntu.com/security/notices/USN-7294-1, https://ubuntu.com/security/notices/USN-7295-1, https://ubuntu.com/security/notices/USN-7301-1, https://ubuntu.com/security/notices/USN-7303-1, https://ubuntu.com/security/notices/USN-7304-1, https://ubuntu.com/security/notices/USN-7294-2, https://ubuntu.com/security/notices/USN-7294-3, https://ubuntu.com/security/notices/USN-7303-2, https://ubuntu.com/security/notices/USN-7311-1, https://ubuntu.com/security/notices/USN-7303-3, https://ubuntu.com/security/notices/USN-7294-4, https://ubuntu.com/security/notices/USN-7384-1, https://ubuntu.com/security/notices/USN-7385-1, https://ubuntu.com/security/notices/USN-7386-1, https://ubuntu.com/security/notices/USN-7393-1, https://ubuntu.com/security/notices/USN-7384-2, https://ubuntu.com/security/notices/USN-7401-1, https://ubuntu.com/security/notices/USN-7403-1, https://ubuntu.com/security/notices/USN-7413-1, https://ubuntu.com/security/notices/USN-7468-1, https://ubuntu.com/security/notices/USN-7539-1, https://ubuntu.com/security/notices/USN-7540-1
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
