tracing: Consider the NULL character when validating the event length
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.3epss 0.2%
exploitation probability
0.2%top 86% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
tracing: Consider the NULL character when validating the event length
strlen() returns a string length excluding the null byte. If the string
length equals to the maximum buffer length, the buffer will have no
space for the NULL terminating character.
This commit checks this condition and returns failure for it.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
Affected products
Linux · LinuxReferences
https://cert-portal.siemens.com/productcert/html/ssa-265688.htmlhttps://git.kernel.org/stable/c/02874ca52df2ca2423ba6122039315ed61c25972https://git.kernel.org/stable/c/0b6e2e22cb23105fcb171ab92f0f7516c69c8471https://git.kernel.org/stable/c/5e3231b352725ff4a3a0095e6035af674f2d8725https://git.kernel.org/stable/c/5fd942598ddeed9a212d1ff41f9f5b47bcc990a7https://git.kernel.org/stable/c/a14a075a14af8d622c576145455702591bdde09dhttps://git.kernel.org/stable/c/b86b0d6eea204116e4185acc35041ca4ff11a642https://git.kernel.org/stable/c/f4ed40d1c669bba1a54407d8182acdc405683f29https://lists.debian.org/debian-lts-announce/2025/01/msg00001.htmlhttps://lists.debian.org/debian-lts-announce/2025/03/msg00002.html