In the Linux kernel, the following vulnerability has been resolved:
smackfs: restrict bytes count in smk_set_cipso()
Oops, I failed to update subject line.
From 07571157c91b98ce1a4aa70967531e64b78e8346 Mon Sep 17 00:00:00 2001 Date: Mon, 12 Apr 2021 22:25:06 +0900 Subject: [PATCH] smackfs: restrict bytes count in smk_set_cipso()
Commit 7ef4c19d245f3dc2 ("smackfs: restrict bytes count in smackfs write functions") missed that count > SMK_CIPSOMAX check applies to only format == SMK_FIXED24_FMT case.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | May 21, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 21, 2024 |
| Ubuntu | — | Upgrade linux-aws-hweUpgrade linux-gkeopUpgrade linuxUpgrade linux-aws-5.4Upgrade linux-gcp-4.15Upgrade linux-aws-fipsUpgrade linux-gcp-5.4Upgrade linux-azure-fde-5.15Upgrade linux-gcp-fipsUpgrade linux-hwe-5.4Upgrade linux-hweUpgrade linux-azure-fipsUpgrade linux-oracle-5.4Upgrade linux-gcpUpgrade linux-raspiUpgrade linux-azure-4.15Upgrade linux-bluefieldUpgrade linux-raspi-5.4Upgrade linux-oracleUpgrade linux-azure-5.4Upgrade linux-awsUpgrade linux-kvmUpgrade linux-azureUpgrade linux-fips | Nov 19, 2024 | May 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub