CVE-2023-52436

In the Linux kernel, the following vulnerability has been resolved: f2fs: explicitly null-terminate the xattr list When setting an xattr, explicitly null-terminate the xattr list. This eliminates the fragile assumption that the unused xattr space is always zeroed.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

19 Apr 2024, 17:36

Type Values Removed Values Added
CWE NVD-CWE-Other
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: f2fs: termina explícitamente en nulo la lista xattr Al configurar un xattr, termina explícitamente en nulo la lista xattr. Esto elimina la frágil suposición de que el espacio xattr no utilizado siempre se pone a cero.
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/12cf91e23b126718a96b914f949f2cdfeadc7b2a - () https://git.kernel.org/stable/c/12cf91e23b126718a96b914f949f2cdfeadc7b2a - Patch
References () https://git.kernel.org/stable/c/16ae3132ff7746894894927c1892493693b89135 - () https://git.kernel.org/stable/c/16ae3132ff7746894894927c1892493693b89135 - Patch
References () https://git.kernel.org/stable/c/2525d1ba225b5c167162fa344013c408e8b4de36 - () https://git.kernel.org/stable/c/2525d1ba225b5c167162fa344013c408e8b4de36 - Patch
References () https://git.kernel.org/stable/c/32a6cfc67675ee96fe107aeed5af9776fec63f11 - () https://git.kernel.org/stable/c/32a6cfc67675ee96fe107aeed5af9776fec63f11 - Patch
References () https://git.kernel.org/stable/c/3e47740091b05ac8d7836a33afd8646b6863ca52 - () https://git.kernel.org/stable/c/3e47740091b05ac8d7836a33afd8646b6863ca52 - Patch
References () https://git.kernel.org/stable/c/5de9e9dd1828db9b8b962f7ca42548bd596deb8a - () https://git.kernel.org/stable/c/5de9e9dd1828db9b8b962f7ca42548bd596deb8a - Patch
References () https://git.kernel.org/stable/c/e26b6d39270f5eab0087453d9b544189a38c8564 - () https://git.kernel.org/stable/c/e26b6d39270f5eab0087453d9b544189a38c8564 - Patch
References () https://git.kernel.org/stable/c/f6c30bfe5a49bc38cae985083a11016800708fea - () https://git.kernel.org/stable/c/f6c30bfe5a49bc38cae985083a11016800708fea - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

20 Feb 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-20 21:15

Updated : 2024-04-19 17:36


NVD link : CVE-2023-52436

Mitre link : CVE-2023-52436

CVE.ORG link : CVE-2023-52436


JSON object : View

Products Affected

linux

  • linux_kernel