CVE-2024-53234

Source
https://cve.org/CVERecord?id=CVE-2024-53234
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53234.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-53234
Downstream
Related
Published
2024-12-27T13:50:20.909Z
Modified
2026-03-20T12:40:50.242088Z
Summary
erofs: handle NONHEAD !delta[1] lclusters gracefully
Details

In the Linux kernel, the following vulnerability has been resolved:

erofs: handle NONHEAD !delta[1] lclusters gracefully

syzbot reported a WARNING in iomapiterdone: iomapfiemap+0x73b/0x9b0 fs/iomap/fiemap.c:80 ioctlfiemap fs/ioctl.c:220 [inline]

Generally, NONHEAD lclusters won't have delta[1]==0, except for crafted images and filesystems created by pre-1.0 mkfs versions.

Previously, it would immediately bail out if delta[1]==0, which led to inadequate decompressed lengths (thus FIEMAP is impacted). Treat it as delta[1]=1 to work around these legacy mkfs versions.

lclusterbits > 14 is illegal for compact indexes, error out too.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/53xxx/CVE-2024-53234.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d95ae5e25326092d61613acf98280270dde22778
Fixed
75a0a6dde803e7a3af700da8da9a361b49f69eba
Fixed
f466641debcbea8bdf78d1b63a6270aadf9301bf
Fixed
480c6c7b55aeacac800bc2a0d321ff53273045e5
Fixed
daaf68fef4b2ff97928227630021d37b27a96655
Fixed
0bc8061ffc733a0a246b8689b2d32a3e9204f43c
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
96a85becb811ca2ce21a21721f1544d342ae431e
Last affected
8c723eef989bc419585237daa467b787ddca5415

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53234.json"