CVE-2024-23850Reachable Assertion in Linux

CWE-617Reachable Assertion15 documents8 sources
Severity
5.5MEDIUMNVD
OSV8.1OSV7.5
EPSS
0.0%
top 87.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateApr 16

Description

In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages8 packages

🔴Vulnerability Details

6
OSV
linux-aws-6.5, linux-raspi vulnerabilities2024-04-16
OSV
linux-aws, linux-aws-5.15 vulnerabilities2024-04-16
OSV
linux, linux-aws, linux-azure, linux-azure-6.5, linux-gcp, linux-gcp-6.5, linux-hwe-6.5, linux-laptop, linux-lowlatency, linux-lowlatency-hwe-6.5, linux-oem-6.5, linux-oracle, linux-oracle-6.5, linux-2024-04-09
OSV
linux, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel2024-04-09
OSV
CVE-2024-23850: In btrfs_get_root_ref in fs/btrfs/disk-io2024-01-23

📋Vendor Advisories

7
Ubuntu
Linux kernel vulnerabilities2024-04-16
Ubuntu
Linux kernel (AWS) vulnerabilities2024-04-16
Ubuntu
Linux kernel vulnerabilities2024-04-09
Ubuntu
Linux kernel vulnerabilities2024-04-09
Red Hat
kernel: btrfs_get_root_ref has an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation2024-01-23

💬Community

1
Bugzilla
CVE-2024-23850 kernel: btrfs_get_root_ref has an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation2024-01-24