Lucene search

K
vulnrichmentLinuxVULNRICHMENT:CVE-2024-41077
HistoryJul 29, 2024 - 2:57 p.m.

CVE-2024-41077 null_blk: fix validation of block size

2024-07-2914:57:36
Linux
github.com
1
null_blk vulnerability fix
block size validation
linux kernel
patch
null pointer dereference
cve-2024-41077

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

In the Linux kernel, the following vulnerability has been resolved:

null_blk: fix validation of block size

Block size should be between 512 and PAGE_SIZE and be a power of 2. The current
check does not validate this, so update the check.

Without this patch, null_blk would Oops due to a null pointer deref when
loaded with bs=1536 [1].

[axboe: remove unnecessary braces and != 0 check]

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial