CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's statmount_mnt_idmap() function, which can lead to a slab out-of-bounds write due to improper handling of sequence buffer overflow. This flaw allows for potential memory corruption, which could be exploited to execute arbitrary code or cause system instability. Organizations utilizing affected Linux kernel versions should prioritize patching this vulnerability to mitigate the risk of exploitation.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap statmount_mnt_idmap() writes one mapping with seq_printf() and then manually advances seq->count to include the NUL separator. If seq_printf() overflows, seq_set_overflow() sets seq->count to seq->size. The manual seq->count++ changes this to seq->size + 1. seq_has_overflowed() then no longer detects the overflow. The corrupted count returns to statmount_string(), which later executes: seq->buf[seq->count++] = '\0'; This causes a 1-byte NULL out-of-bounds write on the dynamically allocated seq buffer. Fix this by checking for overflow immediately after seq_printf().