vulnerability

Oracle Linux: CVE-2024-41019: ELSA-2024-12815: Unbreakable Enterprise kernel security update (IMPORTANT)

Severity
6
CVSS
(AV:L/AC:L/Au:S/C:C/I:N/A:C)
Published
Jul 29, 2024
Added
Nov 21, 2024
Modified
Dec 3, 2025

Description

In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Validate ff offset
This adds sanity checks for ff offset. There is a check
on rt->first_free at first, but walking through by ff
without any check. If the second ff is a large offset.
We may encounter an out-of-bound read.
A flaw was found in the `fs/ntfs3` module in the Linux kernel. This issue involved inadequate validation of the `ff` offset, which could lead to out-of-bounds reads if the offset was excessively large. This flaw posed risks of crashes and information leaks, and has been addressed by adding sanity checks to validate the `ff` offset before use, ensuring safer memory access and improving system stability.

Solution

oracle-linux-upgrade-kernel-uek
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.