Select your cookie preferences

We use cookies and similar tools to enhance your experience, provide our services, deliver relevant advertising, and make improvements. Approved third parties also use these tools to help us deliver advertising and provide certain site features.

CVE-2024-26736

Public on 2024-04-03
Modified on 2024-05-17
Description

In the Linux kernel, the following vulnerability has been resolved: afs: Increase buffer size in afs_update_volume_status() The max length of volume->vid value is 20 characters. So increase idbuf[] size up to 24 to avoid overflow. Found by Linux Verification Center (linuxtesting.org) with SVACE. [DH: Actually, it's 20 + NUL, so increase it to 24 and use snprintf()]

Severity
Medium
See what this means
CVSS v3 Base Score
5.5
See breakdown
Continue reading

Affected Packages

Platform Package Release Date Advisory
Amazon Linux 2 - Kernel-5.10 Extra kernel 2024-03-27 21:47 ALAS2KERNEL-5.10-2024-052
Amazon Linux 2 - Kernel-5.10 Extra kernel 2024-12-05 01:00 ALAS2KERNEL-5.10-2024-076
Amazon Linux 2 - Kernel-5.4 Extra kernel 2024-05-23 23:02 ALAS2KERNEL-5.4-2024-068

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H