Aller au contenu

Fiche vulnérabilité

CVE-2024-57850 : faille élevée linux linux kernel (CVSS 7.8)

Description

In the Linux kernel, the following vulnerability has been resolved: jffs2: Prevent rtime decompress memory corruption The rtime decompression routine does not fully check bounds during the entirety of the decompression pass and can corrupt memory outside the decompression buffer if the compressed data is corrupted. This adds the required check to prevent this failure mode.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
11 janv. 2025
Dernière mise à jour
4 août 2026

Produits concernés

  • linux linux kernel

Références

Rechercher une autre vulnérabilité dans la base CVE