CVE-2025-39840
Description
In the Linux kernel, the following vulnerability has been resolved:audit: fix out-of-bounds read in audit_compare_dname_path()When a watch on dir=/ is combined with an fsnotify event for asingle-character name directly under / (e.g., creating /a), anout-of-bounds read can occur in audit_compare_dname_path().The helper parent_len() returns 1 for /. In audit_compare_dname_path(),when parentlen equals the full path length (1), the code sets p = path + 1and pathlen = 1 - 1 = 0. The subsequent loop then dereferencesp[pathlen - 1] (i.e., p[-1]), causing an out-of-bounds read.Fix this by adding a pathlen > 0 check to the while loop conditionto prevent the out-of-bounds access.[PM: subject tweak, sign-off email fixes]
Risk Information
Associated Vulnerability
No records foundPatch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234