CVE-2024-26828
In the Linux kernel, the following vulnerability has been resolved: cifs: fix underflow in parse_server_interfaces() In this loop, we step through the buffer and after each item we check if the size_left is greater than the minimum size we need.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: cifs: fix underflow in parse_server_interfaces() In this loop, we step through the buffer and after each item we check if the size_left is greater than the minimum size we need. However, the problem is that "bytes_left" is type ssize_t while sizeof() is type size_t. That means that because of type promotion, the comparison is done as an unsigned and if we have negative bytes left the loop continues instead of ending.
- CVSS 3.1
- 9.4 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
- EPSS
- 0.75% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-191
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/7190353835b4a219abb70f90b06cdcae97f11512Patch
- https://git.kernel.org/stable/c/cffe487026be13eaf37ea28b783d9638ab147204Patch
- https://git.kernel.org/stable/c/df2af9fdbc4ddde18a3371c4ca1a86596e8be301Patch
- https://git.kernel.org/stable/c/f7ff1c89fb6e9610d2b01c1821727729e6609308Patch
- https://git.kernel.org/stable/c/7190353835b4a219abb70f90b06cdcae97f11512Patch
- https://git.kernel.org/stable/c/cffe487026be13eaf37ea28b783d9638ab147204Patch
- https://git.kernel.org/stable/c/df2af9fdbc4ddde18a3371c4ca1a86596e8be301Patch
- https://git.kernel.org/stable/c/f7ff1c89fb6e9610d2b01c1821727729e6609308Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.