CVE-2024-26981
Published: May 1, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix OOB in nilfs_set_de_type The size of the nilfs_type_by_mode array in the fs/nilfs2/dir.c file is defined as "S_IFMT >> S_SHIFT", but the nilfs_set_de_type() function, which uses this array, specifies the index to read from the array in the same way as "(mode & S_IFMT) >> S_SHIFT". static void nilfs_set_de_type(struct nilfs_dir_entry *de, struct inode *inode) { umode_t mode = inode->i_mode; de->file_type = nilfs_type_by_mode[(mode & S_IFMT)>>S_SHIFT]; // oob } However, when the index is determined this way, an out-of-bounds (OOB) error occurs by referring to an index that is 1 larger than the array size when the condition "mode & S_IFMT == S_IFMT" is satisfied. Therefore, a patch to resize the nilfs_type_by_mode array should be applied to prevent OOB errors.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 2ba466d74ed74f073257f86e61519cb8f8f46184 - < 054f29e9ca05be3906544c5f2a2c7321c30a4243affected 2ba466d74ed74f073257f86e61519cb8f8f46184 - < 90f43980ea6be4ad903e389be9a27a2a0018f1c8affected 2ba466d74ed74f073257f86e61519cb8f8f46184 - < 7061c7efbb9e8f11ce92d6b4646405ea2b0b4de1affected 2ba466d74ed74f073257f86e61519cb8f8f46184 - < bdbe483da21f852c93b22557b146bc4d989260f0affected 2ba466d74ed74f073257f86e61519cb8f8f46184 - < 897ac5306bbeb83e90c437326f7044c79a17c611+3 more versions |
Linux | Linux | affected 2.6.30unaffected 0 - < 2.6.30unaffected 4.19.313 - <= 4.19.*unaffected 5.4.275 - <= 5.4.*unaffected 5.10.216 - <= 5.10.*+5 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now