kernel CVE-2024-23851
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.19.3
Patched versions
1.19.3
kernel-6.1
(bottlerocket)
< 1.19.3
1.19.3
A flaw was found in copy_params in drivers/md/dm-ioctl.c in the Linux kernel, where it can attempt to allocate more than INT_MAX bytes and crash due to a missing param_kernel→data_size check.