CVE-2024-38604: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: block: refine the EOF check in blkdev_iomap_begin blkdev_iomap_begin rounds down the offset to the logical block size before stashing it in iomap->offset and checking that it still is inside the inode size. Check the i_size check to the raw pos value so that we don't try a zero size write if iter->pos is unaligned.
Affected products
- Linux Linux Kernel: from 6.6, before 6.6.33 (fixed in 6.6.33); from 6.7, before 6.8.12 (fixed in 6.8.12); from 6.9, before 6.9.3 (fixed in 6.9.3)
Published 2024-06-19. Last modified 2026-06-17.