CVE-2024-42104Use After Free in Linux

CWE-416Use After Free57 documents6 sources
Severity
7.8HIGHNVD
OSV5.5OSV5.3
EPSS
0.0%
top 98.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 30
Latest updateDec 12

Description

In the Linux kernel, the following vulnerability has been resolved: nilfs2: add missing check for inode numbers on directory entries Syzbot reported that mounting and unmounting a specific pattern of corrupted nilfs2 filesystem images causes a use-after-free of metadata file inodes, which triggers a kernel bug in lru_add_fn(). As Jan Kara pointed out, this is because the link count of a metadata file gets corrupted to 0, and nilfs_evict_inode(), which is called from iput(), tries to delete th

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDlinux/linux_kernel4.205.4.280+6
Debianlinux/linux_kernel< 5.10.223-1+3
Ubuntulinux/linux_kernel< 5.4.0-195.215+4
CVEListV5linux/linux2ba466d74ed74f073257f86e61519cb8f8f46184c33c2b0d92aa1c2262d999b2598ad6fbd53bd479+8
debiandebian/linux< linux 6.1.98-1 (bookworm)

Patches

🔴Vulnerability Details

28
OSV
linux-gkeop vulnerabilities2024-12-12
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2024-12-10
OSV
linux-oracle vulnerabilities2024-11-25
OSV
linux-azure vulnerabilities2024-11-20
OSV
linux-lowlatency, linux-lowlatency-hwe-6.8 vulnerabilities2024-11-19

📋Vendor Advisories

28
Ubuntu
Linux kernel (GKE) vulnerabilities2024-12-12
Ubuntu
Linux kernel vulnerabilities2024-12-10
Ubuntu
Linux kernel (Oracle) vulnerabilities2024-11-25
Ubuntu
Linux kernel (Azure) vulnerabilities2024-11-20
Ubuntu
Linux kernel vulnerabilities2024-11-19