In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Validate ff offset
This adds sanity checks for ff offset. There is a check on rt->first_free at first, but walking through by ff without any check. If the second ff is a large offset. We may encounter an out-of-bound read.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"259491304723412994820943015978324121980",
"94425477361319623824312292026982029260",
"32943594673739502732600469983144563952",
"207189536944331842715032902093067310946",
"239141751711421027064647507273939781919",
"75626009765289889616034305127530151089",
"31811632903940171473647989014400428502",
"154194036213247873202131638463065312421"
]
},
"signature_type": "Line",
"target": {
"file": "fs/ntfs3/fslog.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6ae7265a7b816879fd0203e83b5030d3720bbb7a",
"id": "CVE-2024-41019-222b79c1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"259491304723412994820943015978324121980",
"94425477361319623824312292026982029260",
"32943594673739502732600469983144563952",
"207189536944331842715032902093067310946",
"239141751711421027064647507273939781919",
"75626009765289889616034305127530151089",
"31811632903940171473647989014400428502",
"154194036213247873202131638463065312421"
]
},
"signature_type": "Line",
"target": {
"file": "fs/ntfs3/fslog.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@35652dfa8cc9a8a900ec0f1e0395781f94ffc5f0",
"id": "CVE-2024-41019-72eba959"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"259491304723412994820943015978324121980",
"94425477361319623824312292026982029260",
"32943594673739502732600469983144563952",
"207189536944331842715032902093067310946",
"239141751711421027064647507273939781919",
"75626009765289889616034305127530151089",
"31811632903940171473647989014400428502",
"154194036213247873202131638463065312421"
]
},
"signature_type": "Line",
"target": {
"file": "fs/ntfs3/fslog.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@617cf144c206f98978ec730b17159344fd147cb4",
"id": "CVE-2024-41019-80148632"
},
{
"digest": {
"function_hash": "138845440110076183316220909808096701085",
"length": 955.0
},
"signature_type": "Function",
"target": {
"function": "check_rstbl",
"file": "fs/ntfs3/fslog.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@82c94e6a7bd116724738aa67eba6f5fedf3a3319",
"id": "CVE-2024-41019-8d87ed54"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"259491304723412994820943015978324121980",
"94425477361319623824312292026982029260",
"32943594673739502732600469983144563952",
"207189536944331842715032902093067310946",
"239141751711421027064647507273939781919",
"75626009765289889616034305127530151089",
"31811632903940171473647989014400428502",
"154194036213247873202131638463065312421"
]
},
"signature_type": "Line",
"target": {
"file": "fs/ntfs3/fslog.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@818a257428644b8873e79c44404d8fb6598d4440",
"id": "CVE-2024-41019-90b2b2f5"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"259491304723412994820943015978324121980",
"94425477361319623824312292026982029260",
"32943594673739502732600469983144563952",
"207189536944331842715032902093067310946",
"239141751711421027064647507273939781919",
"75626009765289889616034305127530151089",
"31811632903940171473647989014400428502",
"154194036213247873202131638463065312421"
]
},
"signature_type": "Line",
"target": {
"file": "fs/ntfs3/fslog.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@82c94e6a7bd116724738aa67eba6f5fedf3a3319",
"id": "CVE-2024-41019-b00210fe"
},
{
"digest": {
"function_hash": "138845440110076183316220909808096701085",
"length": 955.0
},
"signature_type": "Function",
"target": {
"function": "check_rstbl",
"file": "fs/ntfs3/fslog.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@818a257428644b8873e79c44404d8fb6598d4440",
"id": "CVE-2024-41019-c4125413"
},
{
"digest": {
"function_hash": "138845440110076183316220909808096701085",
"length": 955.0
},
"signature_type": "Function",
"target": {
"function": "check_rstbl",
"file": "fs/ntfs3/fslog.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@50c47879650b4c97836a0086632b3a2e300b0f06",
"id": "CVE-2024-41019-ce3db2d7"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"259491304723412994820943015978324121980",
"94425477361319623824312292026982029260",
"32943594673739502732600469983144563952",
"207189536944331842715032902093067310946",
"239141751711421027064647507273939781919",
"75626009765289889616034305127530151089",
"31811632903940171473647989014400428502",
"154194036213247873202131638463065312421"
]
},
"signature_type": "Line",
"target": {
"file": "fs/ntfs3/fslog.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@50c47879650b4c97836a0086632b3a2e300b0f06",
"id": "CVE-2024-41019-d931df8a"
},
{
"digest": {
"function_hash": "138845440110076183316220909808096701085",
"length": 955.0
},
"signature_type": "Function",
"target": {
"function": "check_rstbl",
"file": "fs/ntfs3/fslog.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6ae7265a7b816879fd0203e83b5030d3720bbb7a",
"id": "CVE-2024-41019-eade6c6a"
},
{
"digest": {
"function_hash": "138845440110076183316220909808096701085",
"length": 955.0
},
"signature_type": "Function",
"target": {
"function": "check_rstbl",
"file": "fs/ntfs3/fslog.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@35652dfa8cc9a8a900ec0f1e0395781f94ffc5f0",
"id": "CVE-2024-41019-eca293c3"
},
{
"digest": {
"function_hash": "138845440110076183316220909808096701085",
"length": 955.0
},
"signature_type": "Function",
"target": {
"function": "check_rstbl",
"file": "fs/ntfs3/fslog.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@617cf144c206f98978ec730b17159344fd147cb4",
"id": "CVE-2024-41019-fd9bcf25"
}
]