CVE-2024-46777

MEDIUM EPSS 15.0%
Published Sep 18, 20241y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Sep 18, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: udf: Avoid excessive partition lengths Avoid mounting filesystems where the partition would overflow the 32-bits used for block number. Also refuse to mount filesystems where the partition length is so large we cannot safely index bits in a block bitmap.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
15.0% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 7

VendorProductVersionRange
linuxlinux_kernel* <4.19.322
linuxlinux_kernel*≥4.20  –  <5.4.284
linuxlinux_kernel*≥5.5  –  <5.10.226
linuxlinux_kernel*≥5.11  –  <5.15.167
linuxlinux_kernel*≥5.16  –  <6.1.110
linuxlinux_kernel*≥6.2  –  <6.6.51
linuxlinux_kernel*≥6.7  –  <6.10.10

References 10

  • git.kernel.org https://git.kernel.org/stable/c/0173999123082280cf904bd640015951f194a294
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/1497a4484cdb2cf6c37960d788fb6ba67567bdb7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2ddf831451357c6da4b64645eb797c93c1c054d1
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/551966371e17912564bc387fbeb2ac13077c3db1
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/925fd8ee80d5348a5e965548e5484d164d19221d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a56330761950cb83de1dfb348479f20c56c95f90
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c0c23130d38e8bc28e9ef581443de9b1fc749966
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ebbe26fd54a9621994bc16b14f2ba8f84c089693
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/0173999123082280cf904bd640015951f194a294
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/1497a4484cdb2cf6c37960d788fb6ba67567bdb7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2ddf831451357c6da4b64645eb797c93c1c054d1
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/551966371e17912564bc387fbeb2ac13077c3db1
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/925fd8ee80d5348a5e965548e5484d164d19221d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a56330761950cb83de1dfb348479f20c56c95f90
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c0c23130d38e8bc28e9ef581443de9b1fc749966
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ebbe26fd54a9621994bc16b14f2ba8f84c089693
    Patch