cbcvebase.
CVE-2024-26601
published 2024-02-26

CVE-2024-26601: In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed if under fc replay This mostly reverts…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.1th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed if under fc replay This mostly reverts commit 6bd97bf273bd ("ext4: remove redundant mb_regenerate_buddy()") and reintroduces mb_regenerate_buddy(). Based on code in mb_free_blocks(), fast commit replay can end up marking as free blocks that are already marked as such. This causes corruption of the buddy bitmap so we need to regenerate it in that case.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 0983142c5f17a62055ec851372273c3bc77e4788 < 94ebf71bddbcd4ab1ce43ae32c6cb66396d2d51a94ebf71bddbcd4ab1ce43ae32c6cb66396d2d51a
linuxlinux>= 5.10.181 < 5.10.2115.10.211
linuxlinux>= 6bd97bf273bdb4944904e57480f6545bca48ad77 < c1317822e2de80e78f137d3a2d99febab1b80326c1317822e2de80e78f137d3a2d99febab1b80326
linuxlinux>= 6bd97bf273bdb4944904e57480f6545bca48ad77 < 78327acd4cdc4a1601af718b781eece577b6b7d478327acd4cdc4a1601af718b781eece577b6b7d4
linuxlinux>= 6bd97bf273bdb4944904e57480f6545bca48ad77 < ea42d6cffb0dd27a417f410b9d0011e9859328cbea42d6cffb0dd27a417f410b9d0011e9859328cb
linuxlinux>= 6bd97bf273bdb4944904e57480f6545bca48ad77 < 6b0d48647935e4b8c7b75d1eccb9043fcd4ee5816b0d48647935e4b8c7b75d1eccb9043fcd4ee581
linuxlinux>= 6bd97bf273bdb4944904e57480f6545bca48ad77 < c9b528c35795b711331ed36dc3dbee90d5812d4ec9b528c35795b711331ed36dc3dbee90d5812d4e
linuxlinux_kernel< 5.10.2115.10.211
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 5.11.0 < 5.15.1505.15.150
linuxlinux_kernel>= 5.16.0 < 6.1.786.1.78
linuxlinux_kernel>= 6.2.0 < 6.6.176.6.17
linuxlinux_kernel>= 6.7.0 < 6.7.56.7.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.