Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-26973 Details

Description

In the Linux kernel, the following vulnerability has been resolved: fat: fix uninitialized field in nostale filehandles When fat_encode_fh_nostale() encodes file handle without a parent it stores only first 10 bytes of the file handle. However the length of the file handle must be a multiple of 4 so the file handle is actually 12 bytes long and the last two bytes remain uninitialized. This is not great at we potentially leak uninitialized information with the handle to userspace. Properly initialize the full handle length.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://cert-portal.siemens.com/productcert/html/ssa-265688.html siemens-SADP
https://cert-portal.siemens.com/productcert/html/ssa-398330.html siemens-SADP
https://git.kernel.org/stable/c/03a7e3f2ba3ca25f1da1d3898709a08db14c1abb kernel.orgMailing ListPatch
https://git.kernel.org/stable/c/74f852654b8b7866f15323685f1e178d3386c688 kernel.orgMailing ListPatch
https://git.kernel.org/stable/c/9840d1897e28f8733cc1e38f97e044f987dc0a63 kernel.orgMailing ListPatch

see all 22 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-908Use of Uninitialized Resource[email protected]

Affected Products

ProductVersions
linux linux kernel
>= 3.10, < 4.19.312
>= 4.20, < 5.4.274
>= 5.5, < 5.10.215
>= 5.11, < 5.15.154
>= 5.16, < 6.1.84

CPE

  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
debian debian linux
10.0

CPE

  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

12 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-26973
NVD Published Date:
May 1, 2024
NVD Last Modified:
Jun 17, 2026
Source:
kernel.org
CVE-2024-26973 Details - Not Deferred