PT-2025-8098 · Linux+1 · Linux Kernel+1
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 5.17-rc4 through 5.17-rc6
linux-image-5.10.142-1-generic
linux-image-5.10.142-1-hardened
linux-image-5.15.0-33-generic
linux-image-5.15.0-33-hardened
linux-image-5.15.0-33-lowlatency
linux-image-5.15.0-70-generic
linux-image-5.15.0-70-hardened
linux-image-5.15.0-70-lowlatency
Description
An array-index-out-of-bounds issue exists in the Linux kernel when mounting and operating a corrupted image. The root cause is a missing sanity check on the
curseg->alloc type variable within the sanity check curseg() function, which leads to out-of-bounds access of the sbi->block count[] array. This can impact the confidentiality, integrity, and availability of protected information.Recommendations
Update the Linux kernel to a version where the sanity check for
curseg->alloc type has been implemented.
Update linux-image-5.10.142-1-generic to a patched version.
Update linux-image-5.10.142-1-hardened to a patched version.
Update linux-image-5.15.0-33-generic to a patched version.
Update linux-image-5.15.0-33-hardened to a patched version.
Update linux-image-5.15.0-33-lowlatency to a patched version.
Update linux-image-5.15.0-70-generic to a patched version.
Update linux-image-5.15.0-70-hardened to a patched version.
Update linux-image-5.15.0-70-lowlatency to a patched version.Exploit
Fix
Buffer Overflow
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel