cbcvebase.
CVE-2024-41020
published 2024-07-29

CVE-2024-41020: In the Linux kernel, the following vulnerability has been resolved: filelock: Fix fcntl/close race recovery compat path When I wrote commit 3cad1bc01041…

PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.19%
9.5th percentile
In the Linux kernel, the following vulnerability has been resolved: filelock: Fix fcntl/close race recovery compat path When I wrote commit 3cad1bc01041 ("filelock: Remove locks reliably when fcntl/close race is detected"), I missed that there are two copies of the code I was patching: The normal version, and the version for 64-bit offsets on 32-bit kernels. Thanks to Greg KH for stumbling over this while doing the stable backport... Apply exactly the same fix to the compat path for 32-bit kernels.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < a561145f3ae973ebf3e0aee41624e92a6c5cb38da561145f3ae973ebf3e0aee41624e92a6c5cb38d
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < 4c43ad4ab41602201d34c66ac62130fe339d686f4c43ad4ab41602201d34c66ac62130fe339d686f
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < 911cc83e56a2de5a40758766c6a70d6998248860911cc83e56a2de5a40758766c6a70d6998248860
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < 53e21cfa68a7d12de378b7116c75571f73e0dfa253e21cfa68a7d12de378b7116c75571f73e0dfa2
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < f4d0775c6e2f1340ca0725f0337de149aaa989caf4d0775c6e2f1340ca0725f0337de149aaa989ca
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < 73ae349534ebc377328e7d21891e589626c6e82c73ae349534ebc377328e7d21891e589626c6e82c
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < 5b0af8e4c70e4b884bb94ff5f0cd49ecf1273c025b0af8e4c70e4b884bb94ff5f0cd49ecf1273c02
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < ed898f9ca3fa32c56c858b463ceb9d9936cc69c4ed898f9ca3fa32c56c858b463ceb9d9936cc69c4
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < f8138f2ad2f745b9a1c696a05b749eabe44337eaf8138f2ad2f745b9a1c696a05b749eabe44337ea
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.9.12-16.9.12-1
linuxlinux_kernel>= 0 < 6.9.12-16.9.12-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 0 < 4.4.0-263.2974.4.0-263.297

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.