CVE-2024-26736

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-26736
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26736.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26736
Downstream
Related
Published
2024-04-03T17:00:22.693Z
Modified
2025-11-28T02:34:07.004198Z
Summary
afs: Increase buffer size in afs_update_volume_status()
Details

In the Linux kernel, the following vulnerability has been resolved:

afs: Increase buffer size in afsupdatevolume_status()

The max length of volume->vid value is 20 characters. So increase idbuf[] size up to 24 to avoid overflow.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

[DH: Actually, it's 20 + NUL, so increase it to 24 and use snprintf()]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26736.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d2ddc776a4581d900fc3bdc7803b403daae64d88
Fixed
5c27d85a69fa16a08813ba37ddfb4bbc9a1ed6b5
Fixed
d9b5e2b7a8196850383c70d099bfd39e81ab6637
Fixed
e56662160fc24d28cb75ac095cc6415ae1bda43e
Fixed
e8530b170e464017203e3b8c6c49af6e916aece1
Fixed
6e6065dd25b661420fac19c34282b6c626fcd35e
Fixed
d34a5e57632bb5ff825196ddd9a48ca403626dfa
Fixed
6ea38e2aeb72349cad50e38899b0ba6fbcb2af3d

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
5.4.270
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.211
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.150
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.80
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.19
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.7