cbcvebase.
CVE-2024-26955
published 2024-05-01

CVE-2024-26955: In the Linux kernel, the following vulnerability has been resolved: nilfs2: prevent kernel bug at submit_bh_wbc() Fix a bug where nilfs_get_block() returns a…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.1th percentile
In the Linux kernel, the following vulnerability has been resolved: nilfs2: prevent kernel bug at submit_bh_wbc() Fix a bug where nilfs_get_block() returns a successful status when searching and inserting the specified block both fail inconsistently. If this inconsistent behavior is not due to a previously fixed bug, then an unexpected race is occurring, so return a temporary error -EAGAIN instead. This prevents callers such as __block_write_begin_int() from requesting a read into a buffer that is not mapped, which would cause the BUG_ON check for the BH_Mapped flag in submit_bh_wbc() to fail.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 1f5abe7e7dbcd83e73212c6cb135a6106cea6a0b < 91e4c4595fae5e87069e44687ae879091783c18391e4c4595fae5e87069e44687ae879091783c183
linuxlinux>= 1f5abe7e7dbcd83e73212c6cb135a6106cea6a0b < 32eaee72e96590a75445c8a6c7c1057673b47e0732eaee72e96590a75445c8a6c7c1057673b47e07
linuxlinux>= 1f5abe7e7dbcd83e73212c6cb135a6106cea6a0b < f0fe7ad5aff4f0fcf988913313c497de85f1e186f0fe7ad5aff4f0fcf988913313c497de85f1e186
linuxlinux>= 1f5abe7e7dbcd83e73212c6cb135a6106cea6a0b < ca581d237f3b8539c044205bb003de71d75d227cca581d237f3b8539c044205bb003de71d75d227c
linuxlinux>= 1f5abe7e7dbcd83e73212c6cb135a6106cea6a0b < 192e9f9078c96be30b31c4b44d6294b24520fce5192e9f9078c96be30b31c4b44d6294b24520fce5
linuxlinux>= 1f5abe7e7dbcd83e73212c6cb135a6106cea6a0b < 0c8aa4cfda4e4adb15d5b6536d155eca9c9cd44c0c8aa4cfda4e4adb15d5b6536d155eca9c9cd44c
linuxlinux>= 1f5abe7e7dbcd83e73212c6cb135a6106cea6a0b < 48d443d200237782dc82e6b60663ec414ef02e3948d443d200237782dc82e6b60663ec414ef02e39
linuxlinux>= 1f5abe7e7dbcd83e73212c6cb135a6106cea6a0b < 76ffbe911e2798c7296968f5fd72f7bf67207a8d76ffbe911e2798c7296968f5fd72f7bf67207a8d
linuxlinux>= 1f5abe7e7dbcd83e73212c6cb135a6106cea6a0b < 269cdf353b5bdd15f1a079671b0f889113865f20269cdf353b5bdd15f1a079671b0f889113865f20
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 2.6.30 < 4.19.3124.19.312
linuxlinux_kernel>= 4.20 < 5.4.2745.4.274
linuxlinux_kernel>= 5.11 < 5.15.1545.15.154
linuxlinux_kernel>= 5.16 < 6.1.846.1.84
linuxlinux_kernel>= 5.5 < 5.10.2155.10.215
linuxlinux_kernel>= 6.2 < 6.6.246.6.24

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.