cbcvebase.
CVE-2024-26772
published 2024-04-03

CVE-2024-26772: In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal() Places the…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal() Places the logic for checking if the group's block bitmap is corrupt under the protection of the group lock to avoid allocating blocks from the group with a corrupted block bitmap.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < 5a6dcc4ad0f7f7fa8e8d127b5526e7c5f2d38a435a6dcc4ad0f7f7fa8e8d127b5526e7c5f2d38a43
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < 6b92b1bc16d691c95b152c6dbf027ad64315668d6b92b1bc16d691c95b152c6dbf027ad64315668d
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < ffeb72a80a82aba59a6774b0611f792e0ed3b0b7ffeb72a80a82aba59a6774b0611f792e0ed3b0b7
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < 8de8305a25bfda607fc13475ebe84b978c96d7ff8de8305a25bfda607fc13475ebe84b978c96d7ff
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < d639102f4cbd4cb65d1225dba3b9265596aab586d639102f4cbd4cb65d1225dba3b9265596aab586
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < d3bbe77a76bc52e9d4d0a120f1509be36e25c916d3bbe77a76bc52e9d4d0a120f1509be36e25c916
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < 21dbe20589c7f48e9c5d336ce6402bcebfa6d76a21dbe20589c7f48e9c5d336ce6402bcebfa6d76a
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < 832698373a25950942c04a512daa652c18a9b513832698373a25950942c04a512daa652c18a9b513
linuxlinux_kernel< 4.19.3084.19.308
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-186.2065.4.0-186.206
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 4.20 < 5.4.2705.4.270
linuxlinux_kernel>= 5.11 < 5.15.1505.15.150
linuxlinux_kernel>= 5.16 < 6.1.806.1.80
linuxlinux_kernel>= 5.5 < 5.10.2115.10.211
linuxlinux_kernel>= 6.2 < 6.6.196.6.19

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.