cbcvebase.
CVE-2024-27032
published 2024-05-01

CVE-2024-27032: In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential panic during recovery During recovery, if FAULT_BLOCK is on…

PriorityP427medium6.3CVSS 3.1
AVLACHPRLUINSUCHINAH
EPSS
0.29%
21.3th percentile
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential panic during recovery During recovery, if FAULT_BLOCK is on, it is possible that f2fs_reserve_new_block() will return -ENOSPC during recovery, then it may trigger panic. Also, if fault injection rate is 1 and only FAULT_BLOCK fault type is on, it may encounter deadloop in loop of block reservation. Let's change as below to fix these issues: - remove bug_on() to avoid panic. - limit the loop count of block reservation to avoid potential deadloop.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 2a7b12d4705bc308cf18eae2b69ec8db34881cc3 < 8844b2f8a3f0c428b74672f9726f9950b1a7764c8844b2f8a3f0c428b74672f9726f9950b1a7764c
linuxlinux>= 4.19.307 < 4.204.20
linuxlinux>= 5.10.210 < 5.115.11
linuxlinux>= 5.15.149 < 5.165.16
linuxlinux>= 5.4.269 < 5.55.5
linuxlinux>= 6.1.77 < 6.1.836.1.83
linuxlinux>= 6.6.16 < 6.6.236.6.23
linuxlinux>= 6.7.4 < 6.7.116.7.11
linuxlinux>= 956fa1ddc132e028f3b7d4cf17e6bfc8cb36c7fd < f26091a981318b5b7451d61f99bc073a6af8db67f26091a981318b5b7451d61f99bc073a6af8db67
linuxlinux>= 956fa1ddc132e028f3b7d4cf17e6bfc8cb36c7fd < 21ec68234826b1b54ab980a8df6e33c74cfbee5821ec68234826b1b54ab980a8df6e33c74cfbee58
linuxlinux>= b1020a546779139eec5d930e15ce534c1101b89c < fe4de493572a4263554903bf9c3afc5c196e15f0fe4de493572a4263554903bf9c3afc5c196e15f0
linuxlinux>= b29cc6e29b5e6037e1bcd2b2ac67b7d89acd194c < d034810d02a5af8eb74debe29877dcaf5f00fdd1d034810d02a5af8eb74debe29877dcaf5f00fdd1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 4.19.307 < 4.204.20
linuxlinux_kernel>= 5.10.210 < 5.115.11
linuxlinux_kernel>= 5.15.149 < 5.165.16

CVSS provenance

nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_msrc6.3MEDIUM
vendor_redhat6.3MEDIUM
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.