vulnerability
Ubuntu: (Multiple Advisories) (CVE-2024-49900): Linux kernel vulnerabilities
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:L/AC:L/Au:S/C:C/I:N/A:C) | Oct 21, 2024 | Dec 18, 2024 | May 29, 2025 |
Description
In the Linux kernel, the following vulnerability has been resolved:
jfs: Fix uninit-value access of new_ea in ea_buffer
syzbot reports that lzo1x_1_do_compress is using uninit-value:
=====================================================
BUG: KMSAN: uninit-value in lzo1x_1_do_compress+0x19f9/0x2510 lib/lzo/lzo1x_compress.c:178
...
Uninit was stored to memory at:
ea_put fs/jfs/xattr.c:639 [inline]
...
Local variable ea_buf created at:
__jfs_setxattr+0x5d/0x1ae0 fs/jfs/xattr.c:662
__jfs_xattr_set+0xe6/0x1f0 fs/jfs/xattr.c:934
=====================================================
The reason is ea_buf->new_ea is not initialized properly.
Fix this by using memset to empty its content at the beginning
in ea_get().
Solution(s)
References
- CVE-2024-49900
- https://attackerkb.com/topics/CVE-2024-49900
- UBUNTU-USN-7166-1
- UBUNTU-USN-7166-2
- UBUNTU-USN-7166-3
- UBUNTU-USN-7166-4
- UBUNTU-USN-7186-1
- UBUNTU-USN-7186-2
- UBUNTU-USN-7194-1
- UBUNTU-USN-7276-1
- UBUNTU-USN-7277-1
- UBUNTU-USN-7293-1
- UBUNTU-USN-7294-1
- UBUNTU-USN-7294-2
- UBUNTU-USN-7294-3
- UBUNTU-USN-7294-4
- UBUNTU-USN-7295-1
- UBUNTU-USN-7301-1
- UBUNTU-USN-7303-1
- UBUNTU-USN-7303-2
- UBUNTU-USN-7303-3
- UBUNTU-USN-7304-1
- UBUNTU-USN-7310-1
- UBUNTU-USN-7311-1
- UBUNTU-USN-7384-1
- UBUNTU-USN-7384-2
- UBUNTU-USN-7385-1
- UBUNTU-USN-7386-1
- UBUNTU-USN-7393-1
- UBUNTU-USN-7401-1
- UBUNTU-USN-7403-1
- UBUNTU-USN-7413-1
- UBUNTU-USN-7468-1
- UBUNTU-USN-7539-1
- UBUNTU-USN-7540-1

Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.