CVE-2024-36964: fs/9p: only translate RWX permissions for plain 9P2000
In the Linux kernel, the following vulnerability has been resolved:
fs/9p: only translate RWX permissions for plain 9P2000
Garbage in plain 9P2000's perm bits is allowed through, which causes it to be able to set (among others) the suid bit. This was presumably not the intent since the unix extended bits are handled explicitly and conditionally on .u.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36964?
CVE-2024-36964 has been classified as a high-severity vulnerability affecting the Linux kernel.
How do I fix CVE-2024-36964?
To fix CVE-2024-36964, update the Linux kernel to the recommended versions: 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.11-1, or 6.12.12-1.
What are the consequences of CVE-2024-36964?
CVE-2024-36964 can allow unauthorized setting of permission bits, potentially enabling a suid bit to be set on files.
Is CVE-2024-36964 related to any specific Linux systems?
CVE-2024-36964 affects Debian's Linux kernel and its associated versions.
When was CVE-2024-36964 reported?
CVE-2024-36964 was reported and subsequently resolved in recent updates to the Linux kernel.