CVE-2024-26644 — Use of Uninitialized Resource in Linux
Severity
5.5MEDIUMNVD
OSV7.5OSV6.5
EPSS
0.0%
top 99.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 26
Latest updateJun 26
Description
In the Linux kernel, the following vulnerability has been resolved:
btrfs: don't abort filesystem when attempting to snapshot deleted subvolume
If the source file descriptor to the snapshot ioctl refers to a deleted
subvolume, we get the following abort:
BTRFS: Transaction aborted (error -2)
WARNING: CPU: 0 PID: 833 at fs/btrfs/transaction.c:1875 create_pending_snapshot+0x1040/0x1190 [btrfs]
Modules linked in: pata_acpi btrfs ata_piix libata scsi_mod virtio_net blake2b_generic xor net_failove…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages5 packages
▶CVEListV5linux/linuxd68fc57b7e3245cfacf2e3b47acfed1946a11786 — c06941564027bdbc01d2df7f41e333c11cb0482d+7
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
16📋Vendor Advisories
15💬Community
1Bugzilla▶
CVE-2024-26644 kernel: btrfs: don't abort filesystem when attempting to snapshot deleted subvolume↗2024-03-26