PT-2024-35683 · Linux+1 · Linux Kernel+1

Syzbot

·

Published

2024-11-15

·

Updated

2025-01-07

·

CVE-2024-53235

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A null-ptr-deref issue was reported in fuse read args fill by syzbot. The issue affects file-backed mounts over FUSE. Unlike most filesystems, some network filesystems and FUSE need unavoidable valid file pointers for their read I/Os. The vulnerability is related to the erofs filesystem.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-15877
CVE-2024-53235

Affected Products

Linux Kernel
Erofs