PT-2024-30705 · Linux+4 · Linux Kernel+4

Syzbot

·

Published

2024-06-20

·

Updated

2025-02-04

·

CVE-2024-43845

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a bogus checksum computation in the udf rename() function when updating the checksum of the '..' directory entry of a moved directory. This occurs because the diriter.fi passed to udf update tag() only includes struct fileIdentDesc and not the impUse or name fields, causing the checksumming function to checksum random stack contents beyond the end of the structure. However, this is harmless as the subsequent udf fiiter write fi() will recompute the checksum from on-disk buffers where everything is properly included.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01719
CVE-2024-43845
MGASA-2024-0309
MGASA-2024-0310
OESA-2024-2124
OPENSUSE-SU-2024_3551-1
OPENSUSE-SU-2024_3561-1
OPENSUSE-SU-2024_3564-1
SUSE-SU-2024:3551-1
SUSE-SU-2024:3561-1
SUSE-SU-2024:3564-1
SUSE-SU-2025:20073-1
SUSE-SU-2025:20077-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7196-1

Affected Products

Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu