cbcvebase.
CVE-2024-27035
published 2024-05-01

CVE-2024-27035: In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to guarantee persisting compressed blocks by CP If data block in…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
19.7th percentile
In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to guarantee persisting compressed blocks by CP If data block in compressed cluster is not persisted with metadata during checkpoint, after SPOR, the data may be corrupted, let's guarantee to write compressed page by checkpoint.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 4c8ff7095bef64fc47e996a938f7d57f9e077da3 < e54cce8137258a550b49cae45d09e024821fb28de54cce8137258a550b49cae45d09e024821fb28d
linuxlinux>= 4c8ff7095bef64fc47e996a938f7d57f9e077da3 < 82704e598d7b33c7e45526e34d3c585426319bed82704e598d7b33c7e45526e34d3c585426319bed
linuxlinux>= 4c8ff7095bef64fc47e996a938f7d57f9e077da3 < c3311694b9bcced233548574d414c91d39214684c3311694b9bcced233548574d414c91d39214684
linuxlinux>= 4c8ff7095bef64fc47e996a938f7d57f9e077da3 < 57e8b17d0522c8f4daf0c4d9969b4d735803353257e8b17d0522c8f4daf0c4d9969b4d7358033532
linuxlinux>= 4c8ff7095bef64fc47e996a938f7d57f9e077da3 < 8a430dd49e9cb021372b0ad91e60aeef9c6ced008a430dd49e9cb021372b0ad91e60aeef9c6ced00
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 5.6 < 6.1.836.1.83
linuxlinux_kernel>= 6.2 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.