cbcvebase.
CVE-2024-39276
published 2024-06-25

CVE-2024-39276: In the Linux kernel, the following vulnerability has been resolved: ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find() Syzbot reports a…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.23%
14.3th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find() Syzbot reports a warning as follows: WARNING: CPU: 0 PID: 5075 at fs/mbcache.c:419 mb_cache_destroy+0x224/0x290 Modules linked in: CPU: 0 PID: 5075 Comm: syz-executor199 Not tainted 6.9.0-rc6-gb947cc5bf6d7 RIP: 0010:mb_cache_destroy+0x224/0x290 fs/mbcache.c:419 Call Trace: ext4_put_super+0x6d4/0xcd0 fs/ext4/super.c:1375 generic_shutdown_super+0x136/0x2d0 fs/super.c:641 kill_block_super+0x44/0x90 fs/super.c:1675 ext4_kill_sb+0x68/0xa0 fs/ext4/super.c:7327 [...] This is because when finding an entry in ext4_xattr_block_cache_find(), if ext4_sb_bread() returns -ENOMEM, the ce's e_refcnt, which has already grown in the __entry_find(), won't be put away, and eventually trigger the above issue in mb_cache_destroy() due to reference count leakage. So call mb_cache_entry_put() on the -ENOMEM error branch as a quick fix.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.92 < 4.154.15
linuxlinux>= 4.19.14 < 4.19.3164.19.316
linuxlinux>= 4.20.1 < 4.214.21
linuxlinux>= b878c8a7f08f0c225b6a46ba1ac867e9c5d17807 < 9ad75e78747b5a50dc5a52f0f8e92e920a653f169ad75e78747b5a50dc5a52f0f8e92e920a653f16
linuxlinux>= fb265c9cb49e2074ddcdd4de99728aefdd3b3592 < 896a7e7d0d555ad8b2b46af0c2fa7de7467f9483896a7e7d0d555ad8b2b46af0c2fa7de7467f9483
linuxlinux>= fb265c9cb49e2074ddcdd4de99728aefdd3b3592 < 76dc776153a47372719d664e0fc50d6355791abb76dc776153a47372719d664e0fc50d6355791abb
linuxlinux>= fb265c9cb49e2074ddcdd4de99728aefdd3b3592 < 681ff9a09accd8a4379f8bd30b7a1641ee19bb3e681ff9a09accd8a4379f8bd30b7a1641ee19bb3e
linuxlinux>= fb265c9cb49e2074ddcdd4de99728aefdd3b3592 < e941b712e758f615d311946bf98216e79145ccd9e941b712e758f615d311946bf98216e79145ccd9
linuxlinux>= fb265c9cb49e2074ddcdd4de99728aefdd3b3592 < a95df6f04f2c37291adf26a74205cde0314d4577a95df6f04f2c37291adf26a74205cde0314d4577
linuxlinux>= fb265c9cb49e2074ddcdd4de99728aefdd3b3592 < b37c0edef4e66fb21a2fbc211471195a383e5ab8b37c0edef4e66fb21a2fbc211471195a383e5ab8
linuxlinux>= fb265c9cb49e2074ddcdd4de99728aefdd3b3592 < 0c0b4a49d3e7f49690a6827a41faeffad5df7e210c0b4a49d3e7f49690a6827a41faeffad5df7e21
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 4.14.92 < 4.154.15
linuxlinux_kernel>= 4.19.14 < 4.19.3164.19.316
linuxlinux_kernel4.20.1 – 5.4.278

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.