CVE-2024-56596: jfs: fix array-index-out-of-bounds in jfs_readdir
In the Linux kernel, the following vulnerability has been resolved:
jfs: fix array-index-out-of-bounds in jfsreaddir
The stbl might contain some invalid values. Added a check to return error code in that case.
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56596?
CVE-2024-56596 is classified as a moderate severity vulnerability due to its potential impact on system integrity.
How do I fix CVE-2024-56596?
To fix CVE-2024-56596, update the Linux kernel to a patched version beyond the specified vulnerable versions.
What does CVE-2024-56596 affect?
CVE-2024-56596 affects multiple versions of the Linux kernel ranging from 5.4.287 to versions before 6.6.66.
What type of vulnerability is CVE-2024-56596?
CVE-2024-56596 is an array-index-out-of-bounds vulnerability in the jfs_readdir implementation of the Linux kernel.
How can I determine if my system is vulnerable to CVE-2024-56596?
To determine if your system is vulnerable to CVE-2024-56596, check the kernel version against the affected versions listed in the CVE description.