cbcvebase.
CVE-2024-26773
published 2024-04-03

CVE-2024-26773: In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() Determine if…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.31%
23.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() Determine if the group block bitmap is corrupted before using ac_b_ex in ext4_mb_try_best_found() to avoid allocating blocks from a group with a corrupted block bitmap in the following concurrency and making the situation worse. ext4_mb_regular_allocator ext4_lock_group(sb, group) ext4_mb_good_group // check if the group bbitmap is corrupted ext4_mb_complex_scan_group // Scan group gets ac_b_ex but doesn't use it ext4_unlock_group(sb, group) ext4_mark_group_bitmap_corrupted(group) // The block bitmap was corrupted during // the group unlock gap. ext4_mb_try_best_found ext4_lock_group(ac->ac_sb, group) ext4_mb_use_best_found mb_mark_used // Allocating blocks in block bitmap corrupted group

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < 21f8cfe79f776287459343e9cfa6055af61328ea21f8cfe79f776287459343e9cfa6055af61328ea
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < 260fc96283c0f594de18a1b045faf6d8fb42874d260fc96283c0f594de18a1b045faf6d8fb42874d
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < 927794a02169778c9c2e7b25c768ab3ea8c1dc03927794a02169778c9c2e7b25c768ab3ea8c1dc03
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < 4c21fa60a6f4606f6214a38f50612b17b2f738f54c21fa60a6f4606f6214a38f50612b17b2f738f5
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < f97e75fa4e12b0aa0224e83fcbda8853ac2adf36f97e75fa4e12b0aa0224e83fcbda8853ac2adf36
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < 0184747b552d6b5a14db3b7fcc3b792ce64dedd10184747b552d6b5a14db3b7fcc3b792ce64dedd1
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < a2576ae9a35c078e488f2c573e9e6821d651fbbea2576ae9a35c078e488f2c573e9e6821d651fbbe
linuxlinux>= 163a203ddb36c36d4a1c942aececda0cc8d06aa7 < 4530b3660d396a646aad91a787b6ab37cf604b534530b3660d396a646aad91a787b6ab37cf604b53
linuxlinux_kernel< 4.19.3084.19.308
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-186.2065.4.0-186.206
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 4.20 < 5.4.2705.4.270
linuxlinux_kernel>= 5.11 < 5.15.1505.15.150
linuxlinux_kernel>= 5.16 < 6.1.806.1.80
linuxlinux_kernel>= 5.5 < 5.10.2115.10.211
linuxlinux_kernel>= 6.2 < 6.6.196.6.19

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.