CVE-2024-47670

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-47670
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-47670.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-47670
Downstream
Related
Published
2024-10-09T14:49:11.938Z
Modified
2025-11-28T02:35:05.455418Z
Summary
ocfs2: add bounds checking to ocfs2_xattr_find_entry()
Details

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: add bounds checking to ocfs2xattrfind_entry()

Add a paranoia check to make sure it doesn't stray beyond valid memory region containing ocfs2 xattr entries when scanning for a match. It will prevent out-of-bound access in case of crafted images.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47670.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
b49a786beb11ff740cb9e0c20b999c2a0e1729c2
Fixed
60c0d36189bad58b1a8e69af8781d90009559ea1
Fixed
34759b7e4493d7337cbc414c132cef378c492a2c
Fixed
5bbe51eaf01a5dd6fb3f0dea81791e5dbc6dc6dd
Fixed
9b32539590a8e6400ac2f6e7cf9cbb8e08711a2f
Fixed
1f6e167d6753fe3ea493cdc7f7de8d03147a4d39
Fixed
8e7bef408261746c160853fc27df3139659f5f77
Fixed
9e3041fecdc8f78a5900c3aa51d3d756e73264d6

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.19.323
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.285
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.227
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.168
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.112
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.53
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.10.12