CVE-2024-41018: fs/ntfs3: Add a check for attr_names and oatbl
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Add a check for attrnames and oatbl
Added out-of-bound checking for ane (ATTRNAMEENTRY).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41018?
CVE-2024-41018 has been classified with a medium severity level due to potential out-of-bounds access in the Linux kernel.
How do I fix CVE-2024-41018?
To fix CVE-2024-41018, update your Linux kernel to one of the patched versions: 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.10-1, or 6.12.11-1.
Which versions of Linux are affected by CVE-2024-41018?
CVE-2024-41018 affects various versions of the Linux kernel prior to the mentioned patched versions.
What specific issue does CVE-2024-41018 address in the Linux kernel?
CVE-2024-41018 addresses an out-of-bounds access issue related to attribute names in the NTFS3 filesystem module.
Is CVE-2024-41018 part of a larger set of vulnerabilities?
CVE-2024-41018 appears to be an isolated vulnerability focused on a specific issue in the Linux kernel's NTFS3 filesystem handling.