Executive Summary

Informations
Name CVE-2024-43828 First vendor Publication 2024-08-17
Vendor Cve Last vendor Modification 2024-08-22

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.6 Temporal Score 5.5
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

ext4: fix infinite loop when replaying fast_commit

When doing fast_commit replay an infinite loop may occur due to an uninitialized extent_status struct. ext4_ext_determine_insert_hole() does not detect the replay and calls ext4_es_find_extent_range(), which will return immediately without initializing the 'es' variable.

Because 'es' contains garbage, an integer overflow may happen causing an infinite loop in this function, easily reproducible using fstest generic/039.

This commit fixes this issue by unconditionally initializing the structure in function ext4_es_find_extent_range().

Thanks to Zhang Yi, for figuring out the real problem!

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-43828

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3645

Sources (Detail)

https://git.kernel.org/stable/c/0619f7750f2b178a1309808832ab20d85e0ad121
https://git.kernel.org/stable/c/181e63cd595c688194e07332f9944b3a63193de2
https://git.kernel.org/stable/c/5ed0496e383cb6de120e56991385dce70bbb87c1
https://git.kernel.org/stable/c/81f819c537d29932e4b9267f02411cbc8b355178
https://git.kernel.org/stable/c/907c3fe532253a6ef4eb9c4d67efb71fab58c706
https://git.kernel.org/stable/c/c6e67df64783e99a657ef2b8c834ba2bf54c539c
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
Date Informations
2025-01-08 03:04:31
  • Multiple Updates
2025-01-07 03:04:04
  • Multiple Updates
2024-12-25 03:02:42
  • Multiple Updates
2024-12-12 03:05:38
  • Multiple Updates
2024-11-23 03:02:41
  • Multiple Updates
2024-11-22 03:00:52
  • Multiple Updates
2024-11-20 02:59:12
  • Multiple Updates
2024-11-14 02:59:30
  • Multiple Updates
2024-11-09 02:59:31
  • Multiple Updates
2024-10-26 02:56:55
  • Multiple Updates
2024-10-25 02:58:48
  • Multiple Updates
2024-10-23 02:58:01
  • Multiple Updates
2024-10-03 02:53:17
  • Multiple Updates
2024-10-02 02:51:41
  • Multiple Updates
2024-09-15 02:49:21
  • Multiple Updates
2024-09-12 02:48:52
  • Multiple Updates
2024-09-07 02:47:50
  • Multiple Updates
2024-09-06 02:47:00
  • Multiple Updates
2024-09-04 02:50:11
  • Multiple Updates
2024-08-22 21:27:59
  • Multiple Updates
2024-08-19 13:27:29
  • Multiple Updates
2024-08-17 17:27:28
  • First insertion