CVE-2024-41017: jfs: don't walk off the end of ealist
In the Linux kernel, the following vulnerability has been resolved:
jfs: don't walk off the end of ealist
Add a check before visiting the members of ea to make sure each ea stays within the ealist.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41017?
CVE-2024-41017 has been assessed as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2024-41017?
To remediate CVE-2024-41017, update your Linux kernel to one of the patched versions such as 5.10.223-1, 5.10.226-1, or 6.1.123-1.
What systems are affected by CVE-2024-41017?
CVE-2024-41017 affects specific versions of the Linux kernel, including 5.10.x and 6.1.x series.
What type of vulnerability is CVE-2024-41017?
CVE-2024-41017 is a vulnerability that involves improper validation in the jfs module of the Linux kernel.
Is there a known exploit for CVE-2024-41017?
As of now, there are no publicly disclosed exploits specifically targeting CVE-2024-41017.