CVE-2024-26818: tools/rtla: Fix clang warning about mount_point var size
In the Linux kernel, the following vulnerability has been resolved:
tools/rtla: Fix clang warning about mountpoint var size
clang is reporting this warning:
$ make HOSTCC=clang CC=clang LLVMIAS=1 [...] clang -O -g -DVERSION=\"6.8.0-rc3\" -flto=auto -fexceptions -fstack-protector-strong -fasynchronous-unwind-tables -fstack-clash-protection -Wall -Werror=format-security -Wp,-DFORTIFYSOURCE=2 -Wp,-DGLIBCXXASSERTIONS $(pkg-config --cflags libtracefs) -c -o src/utils.o src/utils.c
src/utils.c:548:66: warning: 'fscanf' may overflow; destination buffer in argument 3 has size 1024, but the corresponding specifier may require size 1025 [-Wfortify-source] 548 | while (fscanf(fp, "%s %" STR(MAXPATH) "s %99s %s %d %d\n", mountpoint, type) == 2) { | ^
Increase mountpoint variable size to MAXPATH+1 to avoid the overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26818?
CVE-2024-26818 has a high severity rating due to the potential impact on system stability and performance.
How do I fix CVE-2024-26818?
To fix CVE-2024-26818, update the Linux kernel to one of the following versions: 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.
Which Linux distributions are affected by CVE-2024-26818?
CVE-2024-26818 affects Debian-based Linux distributions that use the specified kernel versions.
What is the nature of the issue described in CVE-2024-26818?
CVE-2024-26818 is related to a warning generated by clang regarding the size of a variable in the Linux kernel.
Is CVE-2024-26818 a critical vulnerability?
While CVE-2024-26818 is significant, it is categorized as high severity rather than critical, and users should still prioritize updating their systems.