CVE-2024-57943 – Apache Exfat uninitialized page cache write vulnerability

CVE ID : CVE-2024-57943

Published : Jan. 21, 2025, 1:15 p.m. | 1 hour, 2 minutes ago

Description : In the Linux kernel, the following vulnerability has been resolved:

exfat: fix the new buffer was not zeroed before writing

Before writing, if a buffer_head marked as new, its data must
be zeroed, otherwise uninitialized data in the page cache will
be written.

So this commit uses folio_zero_new_buffers() to zero the new
buffers before ->write_end().

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE-2024-57943 – Apache Exfat uninitialized page cache write vulnerability