Lucene search

K
osvGoogleOSV:CVE-2024-40938
HistoryJul 12, 2024 - 1:15 p.m.

CVE-2024-40938

2024-07-1213:15:00
Google
osv.dev
3
linux kernel
vulnerability
cve-2024-40938
landlock
d_parent walk
collect_domain_accesses
root mount point
vfs check
security_path_link
mount point

AI Score

6.6

Confidence

Low

In the Linux kernel, the following vulnerability has been resolved: landlock: Fix d_parent walk The WARN_ON_ONCE() in collect_domain_accesses() can be triggered when trying to link a root mount point. This cannot work in practice because this directory is mounted, but the VFS check is done after the call to security_path_link(). Do not use source directory’s d_parent when the source directory is the mount point. [mic: Fix commit message]