CVE-2024-41019: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate ff offset This adds sanity checks for ff offset. There is a check on rt->first_free at first, but walking through by ff without any check. If the second ff is a large offset. We may encounter an out-of-bound read.

Affected products

  • Linux Linux Kernel: from 5.15, before 5.15.164 (fixed in 5.15.164); from 5.16, before 6.1.102 (fixed in 6.1.102); from 6.2, before 6.6.43 (fixed in 6.6.43); from 6.7, before 6.9.12 (fixed in 6.9.12); from 6.10, before 6.10.2 (fixed in 6.10.2)

Published 2024-07-29. Last modified 2026-08-04.