CVE-2024-36917: block: fix overflow in blk_ioctl_discard()
Published May 30, 2024
·Updated
block: fix overflow in blkioctldiscard()
Affected Software
14 affected componentsFixes available
IBM Security Verify Governance<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager Software Stack<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager Virtual Appliance<=ISVG 10.0.2
IBM Security Verify Governance Identity Manager Container<=ISVG 10.0.2
debian/linux<=5.10.223-1, <=5.10.234-1
6.1.129-16.1.135-16.12.25-16.12.27-1
redhat/kernel<6.1.91
6.1.91
redhat/kernel<6.6.31
6.6.31
redhat/kernel<6.8.10
6.8.10
redhat/kernel<6.9
6.9
Linux Linux kernel>=2.6.28<6.1.91
Linux Linux kernel>=6.2<6.6.31
Linux Linux kernel>=6.7<6.8.10
Linux Linux kernel=6.9-rc1
Linux Linux kernel=6.9-rc2
Remediation
Event History
May 30, 2024
CVE Published
via MITRE·03:29 PM
Data Sourced
via MITRE·03:29 PM
Description
Data Sourced
via NVD·04:15 PM
Description
Data Sourced
via NVD·04:15 PM
RemedySeverityWeaknessAffected Software
Jun 3, 2024
Data Sourced
via Red Hat·12:42 PM
DescriptionSeverityAffected Software
Aug 8, 2024
Data Sourced
via Launchpad·11:25 PM
Description
Apr 27, 2025
Data Sourced
via Ubuntu·12:27 AM
RemedyDescriptionSeverityAffected Software
Sep 20, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36917?
CVE-2024-36917 is classified with a medium severity due to its potential impact on system stability.
2
How do I fix CVE-2024-36917?
To address CVE-2024-36917, users should upgrade their Linux kernel to versions 6.1.91, 6.6.31, 6.8.10, 6.9, or specific Debian versions as outlined by the advisory.
3
What systems are affected by CVE-2024-36917?
CVE-2024-36917 affects various kernel versions across Red Hat and Debian distributions.
4
Can CVE-2024-36917 cause system crashes?
Yes, CVE-2024-36917 may lead to unexpected behavior including potential system crashes under certain conditions.
5
Is CVE-2024-36917 a local or remote vulnerability?
CVE-2024-36917 is considered a local vulnerability, requiring local access to exploit.