CVE-2024-26981

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-26981
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26981.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26981
Downstream
Related
Published
2024-05-01T05:27:06.469Z
Modified
2025-11-28T02:34:44.117366Z
Summary
nilfs2: fix OOB in nilfs_set_de_type
Details

In the Linux kernel, the following vulnerability has been resolved:

nilfs2: fix OOB in nilfssetde_type

The size of the nilfstypebymode array in the fs/nilfs2/dir.c file is defined as "SIFMT >> SSHIFT", but the nilfssetdetype() function, which uses this array, specifies the index to read from the array in the same way as "(mode & SIFMT) >> SSHIFT".

static void nilfssetdetype(struct nilfsdirentry *de, struct inode *inode) { umodet mode = inode->i_mode;

de->file_type = nilfs_type_by_mode[(mode & S_IFMT)>>S_SHIFT]; // oob

}

However, when the index is determined this way, an out-of-bounds (OOB) error occurs by referring to an index that is 1 larger than the array size when the condition "mode & SIFMT == SIFMT" is satisfied. Therefore, a patch to resize the nilfstypeby_mode array should be applied to prevent OOB errors.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26981.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2ba466d74ed74f073257f86e61519cb8f8f46184
Fixed
054f29e9ca05be3906544c5f2a2c7321c30a4243
Fixed
90f43980ea6be4ad903e389be9a27a2a0018f1c8
Fixed
7061c7efbb9e8f11ce92d6b4646405ea2b0b4de1
Fixed
bdbe483da21f852c93b22557b146bc4d989260f0
Fixed
897ac5306bbeb83e90c437326f7044c79a17c611
Fixed
2382eae66b196c31893984a538908c3eb7506ff9
Fixed
90823f8d9ecca3d5fa6b102c8e464c62f416975f
Fixed
c4a7dc9523b59b3e73fd522c73e95e072f876b16

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.30
Fixed
4.19.313
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.275
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.216
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.157
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.88
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.29
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.8.8