CVE-2024-27407

HIGH

Linux Kernel 5.15-6.1.119, 6.2-6.6.18, 6.7-6.7.6 - Buffer Overflow in NTFS3 Attribute Enumeration

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fixed overflow check in mi_enum_attr()

Scores

CVSS v3 8.4
EPSS 0.0027
EPSS Percentile 19.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-120
Status published
Products (15)
linux/Kernel 5.15.0 - 6.1.120linux
linux/Kernel 6.2.0 - 6.6.19linux
linux/Kernel 6.7.0 - 6.7.7linux
Linux/Linux < 5.15
Linux/Linux 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e - 1c0a95d99b1b2b5d842e5abc7ef7eed1193b60d7
Linux/Linux 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e - 652cfeb43d6b9aba5c7c4902bed7a7340df131fb
Linux/Linux 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e - 8c77398c72618101d66480b94b34fe9087ee3d08
Linux/Linux 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e - e99faa97359654b6e4e769246c72cf50a57e05b2
Linux/Linux 5.15
Linux/Linux 6.1.120 - 6.1.*
... and 5 more
Published May 17, 2024
Tracked Since Feb 18, 2026