CVE-2024-41016: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry() xattr in ocfs2 maybe 'non-indexed', which saved with additional space requested. It's better to check if the memory is out of bound before memcmp, although this possibility mainly comes from crafted poisonous images.
Affected products
- Linux Linux Kernel: before 4.19.323 (fixed in 4.19.323); from 4.20, before 5.4.285 (fixed in 5.4.285); from 5.5, before 5.10.227 (fixed in 5.10.227); from 5.11, before 5.15.168 (fixed in 5.15.168); from 5.16, before 6.1.112 (fixed in 6.1.112); from 6.2, before 6.6.53 (fixed in 6.6.53); …
Published 2024-07-29. Last modified 2026-08-04.