VYPR
Medium severity5.5NVD Advisory· Published Jul 29, 2024· Updated Jun 17, 2026

CVE-2024-42084

CVE-2024-42084

Description

In the Linux kernel, the following vulnerability has been resolved:

ftruncate: pass a signed offset

The old ftruncate() syscall, using the 32-bit off_t misses a sign extension when called in compat mode on 64-bit architectures. As a result, passing a negative length accidentally succeeds in truncating to file size between 2GiB and 4GiB.

Changing the type of the compat syscall to the signed compat_off_t changes the behavior so it instead returns -EINVAL.

The native entry point, the truncate() syscall and the corresponding loff_t based variants are all correct already and do not suffer from this mistake.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

46

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.