#VU94237 Out-of-bounds read in Linux kernel - CVE-2024-40955
Published: July 13, 2024 / Updated: May 13, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the EXT4_ATTR_FUNC(), ext4_attr_show() and ext4_attr_store() functions in fs/ext4/sysfs.c, within the mb_avg_fragment_size_order() and ext4_mb_choose_next_group_best_avail() functions in fs/ext4/mballoc.c. A local user can perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/677ff4589f1501578fa903a25bb14831d0607992
- https://git.kernel.org/stable/c/b829687ae1229224262bcabf49accfa2dbf8db06
- https://git.kernel.org/stable/c/13df4d44a3aaabe61cd01d277b6ee23ead2a5206
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.10
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.36