CVE-2024-47723: Linux Kernel
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: jfs: fix out-of-bounds in dbNextAG() and diAlloc() In dbNextAG() , there is no check for the case where bmp->db_numag is greater or same than MAXAG due to a polluted image, which causes an out-of-bounds. Therefore, a bounds check should be added in dbMount(). And in dbNextAG(), a check for the case where agpref is greater than bmp->db_numag should be added, so an out-of-bounds exception should be prevented. Additionally, a check for the case where agno is greater or same than MAXAG should be added in diAlloc() to prevent out-of-bounds.
Affected products
- Linux Linux Kernel: from 2.6.12, before 5.10.227 (fixed in 5.10.227); from 5.11, before 5.15.168 (fixed in 5.15.168); from 5.16, before 6.1.113 (fixed in 6.1.113); from 6.2, before 6.6.54 (fixed in 6.6.54); from 6.7, before 6.10.13 (fixed in 6.10.13); from 6.11, before 6.11.2 (fixed in 6.11.2)
Published 2024-10-21. Last modified 2026-08-04.