In the Linux kernel, the following vulnerability has been resolved:
binfmt_flat: Fix integer overflow bug on 32 bit systems
Most of these sizes and counts are capped at 256MB so the math doesn't
result in an integer overflow. The "relocs" count needs to be checked
as well. Otherwise on 32bit systems the calculation of "full_data"
could be wrong.
full_data = data_len + relocs * sizeof(unsigned long);
References
Configurations
Configuration 1 (hide)
|
History
13 Mar 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
References | () https://git.kernel.org/stable/c/55cf2f4b945f6a6416cc2524ba740b83cc9af25a - Patch | |
References | () https://git.kernel.org/stable/c/8e8cd712bb06a507b26efd2a56155076aa454345 - Patch | |
References | () https://git.kernel.org/stable/c/95506c7f33452450346fbe2975c1359100f854ca - Patch | |
References | () https://git.kernel.org/stable/c/a009378af674b808efcca1e2e67916e79ce866b3 - Patch | |
References | () https://git.kernel.org/stable/c/d17ca8f2dfcf423c439859995910a20e38b86f00 - Patch | |
CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
CWE | CWE-190 | |
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
First Time |
Linux
Linux linux Kernel |
27 Feb 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-27 03:15
Updated : 2025-03-13 13:15
NVD link : CVE-2024-58010
Mitre link : CVE-2024-58010
CVE.ORG link : CVE-2024-58010
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-190
Integer Overflow or Wraparound