PT-2024-33975 · Linux+8 · Linux Kernel+8
Published
2024-10-02
·
Updated
2026-03-27
·
CVE-2024-50143
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.61
Description:
The issue concerns an uninit-value use in
udf get fileshortad and a potential overflow when computing alen in udf current aext. This could lead to later uninit-value use in udf get fileshortad, identified as a KMSAN bug. After applying the patch, the reproducer did not trigger any issues.Recommendations:
For Linux kernel versions prior to 6.6.61, update to version 6.6.61 or later to resolve the issue. As a temporary workaround, consider restricting access to the
udf get fileshortad function and the udf current aext computation until a patch is available. Avoid using the alen variable in the affected udf current aext computation until the issue is resolved.Exploit
Fix
DoS
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu