Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-46777

Опубликовано: 18 сент. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: udf: Avoid excessive partition lengths Avoid mounting filesystems where the partition would overflow the 32-bits used for block number. Also refuse to mount filesystems where the partition length is so large we cannot safely index bits in a block bitmap.

A flaw was found in the Linux kernel's Universal Disk Format (UDF) filesystem. A local attacker could craft a malicious UDF filesystem with excessive partition lengths. When an affected system attempts to mount this filesystem, it could lead to an overflow of the 32-bit block number or an inability to safely index bits in a block bitmap, resulting in a denial of service.

Меры по смягчению последствий

To reduce exposure, avoid mounting untrusted UDF filesystem images. If UDF support is not essential, the udf kernel module can be blacklisted to prevent its automatic loading. To blacklist the udf module:

  1. Create /etc/modprobe.d/blacklist-udf.conf with:
blacklist udf install udf /bin/true
  1. Regenerate the initramfs: dracut -f -v $(uname -r) (for RHEL 8/9) or dracut -f -v (for RHEL 7).
  2. A system reboot is required for the changes to take effect. This action may affect systems that legitimately utilize UDF filesystems.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 8kernelWill not fix
Red Hat Enterprise Linux 8kernel-rtWill not fix
Red Hat Enterprise Linux 9kernelWill not fix
Red Hat Enterprise Linux 9kernel-rtWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2313125kernel: udf: Avoid excessive partition lengths

EPSS

Процентиль: 17%
0.00254
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: udf: Avoid excessive partition lengths Avoid mounting filesystems where the partition would overflow the 32-bits used for block number. Also refuse to mount filesystems where the partition length is so large we cannot safely index bits in a block bitmap.

CVSS3: 7.8
nvd
около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: udf: Avoid excessive partition lengths Avoid mounting filesystems where the partition would overflow the 32-bits used for block number. Also refuse to mount filesystems where the partition length is so large we cannot safely index bits in a block bitmap.

CVSS3: 7.8
debian
около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: u ...

CVSS3: 5.5
github
около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: udf: Avoid excessive partition lengths Avoid mounting filesystems where the partition would overflow the 32-bits used for block number. Also refuse to mount filesystems where the partition length is so large we cannot safely index bits in a block bitmap.

CVSS3: 5.5
fstec
около 2 лет назад

Уязвимость компонента udf ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 17%
0.00254
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2024-46777