cbcvebase.
CVE-2024-40971
published 2024-07-12

CVE-2024-40971: In the Linux kernel, the following vulnerability has been resolved: f2fs: remove clear SB_INLINECRYPT flag in default_options In f2fs_remount, SB_INLINECRYPT…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.30%
22.5th percentile
In the Linux kernel, the following vulnerability has been resolved: f2fs: remove clear SB_INLINECRYPT flag in default_options In f2fs_remount, SB_INLINECRYPT flag will be clear and re-set. If create new file or open file during this gap, these files will not use inlinecrypt. Worse case, it may lead to data corruption if wrappedkey_v0 is enable. Thread A: Thread B: -f2fs_remount -f2fs_file_open or f2fs_new_inode -default_options <- clear SB_INLINECRYPT flag -fscrypt_select_encryption_impl -parse_options <- set SB_INLINECRYPT again

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < 38a82c8d00638bb642bef787eb1d5e0e4d3b7d7138a82c8d00638bb642bef787eb1d5e0e4d3b7d71
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < 724429db09e21ee153fef35e34342279d33df6ae724429db09e21ee153fef35e34342279d33df6ae
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < a9cea0489c562c97cd56bb345e78939f9909e7f4a9cea0489c562c97cd56bb345e78939f9909e7f4
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < eddeb8d941d5be11a9da5637dbe81ac37e8449a2eddeb8d941d5be11a9da5637dbe81ac37e8449a2
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < ae39c8ec4250d2a35ddaab1c40faacfec306ff66ae39c8ec4250d2a35ddaab1c40faacfec306ff66
linuxlinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < ac5eecf481c29942eb9a862e758c0c8b68090c33ac5eecf481c29942eb9a862e758c0c8b68090c33
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 3.8 < 5.10.2215.10.221
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.966.1.96
linuxlinux_kernel>= 6.2 < 6.6.366.6.36
linuxlinux_kernel>= 6.7 < 6.9.76.9.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.