CVE-2024-50143: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: udf: fix uninit-value use in udf_get_fileshortad Check for overflow when computing alen in udf_current_aext to mitigate later uninit-value use in udf_get_fileshortad KMSAN bug[1]. After applying the patch reproducer did not trigger any issue[2]. [1] https://syzkaller.appspot.com/bug?extid=8901c4560b7ab5c2f9df [2] https://syzkaller.appspot.com/x/log.txt?x=10242227980000

Affected products

  • Linux Linux Kernel: before 4.19.323 (fixed in 4.19.323); from 4.20, before 5.4.285 (fixed in 5.4.285); from 5.5, before 5.15.170 (fixed in 5.15.170); from 5.16, before 6.1.115 (fixed in 6.1.115); from 6.2, before 6.6.59 (fixed in 6.6.59); from 6.7, before 6.11.6 (fixed in 6.11.6); …

Published 2024-11-07. Last modified 2026-08-04.