CVE-2024-38599
Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, linux kernel
In the Linux kernel, the following vulnerability has been resolved: jffs2: prevent xattr node from overflowing the eraseblock Add a check to make sure that the requested xattr node size is no larger than the eraseblock minus the cleanmarker. Unlike the usual inode nodes, the xattr nodes aren't split into parts and spread across multiple eraseblocks, which means that a xattr node must not occupy more than one eraseblock. If the requested xattr value is too large, the xattr node can spill onto the next eraseblock, overwriting the nodes and causing errors such as: jffs2: argh. node added in wr...
- CVSS
- 7.1
- EPSS
- 0.24% 15.8% percentile
- CISA KEV
- Not listed
- Published
- 2024.06.19