CVE-2024-38623: fs/ntfs3: Use variable length array instead of fixed size
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Use variable length array instead of fixed size
Should fix smatch warning: ntfssetlabel() error: builtinmemcpy() 'uni->name' too small (20 vs 256)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38623?
CVE-2024-38623 is classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2024-38623?
To mitigate CVE-2024-38623, upgrade to the fixed versions of the Linux package: 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.
What software is affected by CVE-2024-38623?
CVE-2024-38623 affects the Linux kernel versions prior to the patched releases listed under the affected software.
What components does CVE-2024-38623 impact?
CVE-2024-38623 impacts the NTFS file system implementation within the Linux kernel.
Is there a public discussion or report on CVE-2024-38623?
Yes, CVE-2024-38623 has been publicly disclosed as part of the Linux kernel updates.