In the Linux kernel, the following vulnerability has been resolved:
afs: Increase buffer size in afs_update_volume_status()
The max length of volume->vid value is 20 characters.
So increase idbuf[] size up to 24 to avoid overflow.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
[DH: Actually, it’s 20 + NUL, so increase it to 24 and use snprintf()]
[
{
"product": "Linux",
"vendor": "Linux",
"defaultStatus": "unaffected",
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"programFiles": [
"fs/afs/volume.c"
],
"versions": [
{
"version": "d2ddc776a458",
"lessThan": "5c27d85a69fa",
"status": "affected",
"versionType": "git"
},
{
"version": "d2ddc776a458",
"lessThan": "d9b5e2b7a819",
"status": "affected",
"versionType": "git"
},
{
"version": "d2ddc776a458",
"lessThan": "e56662160fc2",
"status": "affected",
"versionType": "git"
},
{
"version": "d2ddc776a458",
"lessThan": "e8530b170e46",
"status": "affected",
"versionType": "git"
},
{
"version": "d2ddc776a458",
"lessThan": "6e6065dd25b6",
"status": "affected",
"versionType": "git"
},
{
"version": "d2ddc776a458",
"lessThan": "d34a5e57632b",
"status": "affected",
"versionType": "git"
},
{
"version": "d2ddc776a458",
"lessThan": "6ea38e2aeb72",
"status": "affected",
"versionType": "git"
}
]
},
{
"product": "Linux",
"vendor": "Linux",
"defaultStatus": "affected",
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"programFiles": [
"fs/afs/volume.c"
],
"versions": [
{
"version": "4.15",
"status": "affected"
},
{
"version": "0",
"lessThan": "4.15",
"status": "unaffected",
"versionType": "custom"
},
{
"version": "5.4.270",
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"versionType": "custom"
},
{
"version": "5.10.211",
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"versionType": "custom"
},
{
"version": "5.15.150",
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"versionType": "custom"
},
{
"version": "6.1.80",
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"versionType": "custom"
},
{
"version": "6.6.19",
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"versionType": "custom"
},
{
"version": "6.7.7",
"lessThanOrEqual": "6.7.*",
"status": "unaffected",
"versionType": "custom"
},
{
"version": "6.8",
"lessThanOrEqual": "*",
"status": "unaffected",
"versionType": "original_commit_for_fix"
}
]
}
]
git.kernel.org/stable/c/5c27d85a69fa16a08813ba37ddfb4bbc9a1ed6b5
git.kernel.org/stable/c/6e6065dd25b661420fac19c34282b6c626fcd35e
git.kernel.org/stable/c/6ea38e2aeb72349cad50e38899b0ba6fbcb2af3d
git.kernel.org/stable/c/d34a5e57632bb5ff825196ddd9a48ca403626dfa
git.kernel.org/stable/c/d9b5e2b7a8196850383c70d099bfd39e81ab6637
git.kernel.org/stable/c/e56662160fc24d28cb75ac095cc6415ae1bda43e
git.kernel.org/stable/c/e8530b170e464017203e3b8c6c49af6e916aece1
lists.debian.org/debian-lts-announce/2024/06/msg00017.html