cbcvebase.
CVE-2024-42115
published 2024-07-30

CVE-2024-42115: In the Linux kernel, the following vulnerability has been resolved: jffs2: Fix potential illegal address access in jffs2_free_inode During the stress testing…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.4th percentile
In the Linux kernel, the following vulnerability has been resolved: jffs2: Fix potential illegal address access in jffs2_free_inode During the stress testing of the jffs2 file system,the following abnormal printouts were found: [ 2430.649000] Unable to handle kernel paging request at virtual address 0069696969696948 [ 2430.649622] Mem abort info: [ 2430.649829] ESR = 0x96000004 [ 2430.650115] EC = 0x25: DABT (current EL), IL = 32 bits [ 2430.650564] SET = 0, FnV = 0 [ 2430.650795] EA = 0, S1PTW = 0 [ 2430.651032] FSC = 0x04: level 0 translation fault [ 2430.651446] Data abort info: [ 2430.651683] ISV = 0, ISS = 0x00000004 [ 2430.652001] CM = 0, WnR = 0 [ 2430.652558] [0069696969696948] address between user and kernel address ranges [ 2430.653265] Internal error: Oops: 96000004 [#1] PREEMPT SMP [ 2430.654512] CPU: 2 PID: 20919 Comm: cat Not tainted 5.15.25-g512f31242bf6 #33 [ 2430.655008] Hardware name: linux,dummy-virt (DT) [ 2430.655517] pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 2430.656142] pc : kfree+0x78/0x348 [ 2430.656630] lr : jffs2_free_inode+0x24/0x48 [ 2430.657051] sp : ffff800009eebd10 [ 2430.657355] x29: ffff800009eebd10 x28: 0000000000000001 x27: 0000000000000000 [ 2430.658327] x26: ffff000038f09d80 x25: 0080000000000000 x24: ffff800009d38000 [ 2430.658919] x23: 5a5a5a5a5a5a5a5a x22: ffff000038f09d80 x21: ffff8000084f0d14 [ 2430.659434] x20: ffff0000bf9a6ac0 x19: 0169696969696940 x18: 0000000000000000 [ 2430.659969] x17: ffff8000b6506000 x16: ffff800009eec000 x15: 0000000000004000 [ 2430.660637] x14: 0000000000000000 x13: 00000001000820a1 x12: 00000000000d1b19 [ 2430.661345] x11: 0004000800000000 x10: 0000000000000001 x9 : ffff8000084f0d14 [ 2430.662025] x8 : ffff0000bf9a6b40 x7 : ffff0000bf9a6b48 x6 : 0000000003470302 [ 2430.662695] x5 : ffff00002e41dcc0 x4 : ffff0000bf9aa3b0 x3 : 0000000003470342 [ 2430.663486] x2 : 0000000000000000 x1 : ffff8000084f0d14 x0 : fffffc0000000000 [ 2430.664217] Call trace: [ 2430.664528] kfree+0x

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.18.140 < 3.193.19
linuxlinux>= 4.14.117 < 4.154.15
linuxlinux>= 4.19.41 < 4.19.3184.19.318
linuxlinux>= 4.4.180 < 4.54.5
linuxlinux>= 4.9.174 < 4.104.10
linuxlinux>= 4fdcfab5b5537c21891e22e65996d4d0dd8ab4ca < 0b3246052e01e61a55bb3a15b76acb006759fe670b3246052e01e61a55bb3a15b76acb006759fe67
linuxlinux>= 4fdcfab5b5537c21891e22e65996d4d0dd8ab4ca < 6d6d94287f6365282bbf41e9a5b52819859707896d6d94287f6365282bbf41e9a5b5281985970789
linuxlinux>= 4fdcfab5b5537c21891e22e65996d4d0dd8ab4ca < 5ca26334fc8a3711fed14db7f9eb1c621be4df655ca26334fc8a3711fed14db7f9eb1c621be4df65
linuxlinux>= 4fdcfab5b5537c21891e22e65996d4d0dd8ab4ca < 751987a5d8ead0cc405fad96e83ebbaa51c82dbc751987a5d8ead0cc405fad96e83ebbaa51c82dbc
linuxlinux>= 4fdcfab5b5537c21891e22e65996d4d0dd8ab4ca < d0bbbf31462a400bef4df33e22de91864f475455d0bbbf31462a400bef4df33e22de91864f475455
linuxlinux>= 4fdcfab5b5537c21891e22e65996d4d0dd8ab4ca < 05fc1ef892f862c1197b11b288bc00f602d2df0c05fc1ef892f862c1197b11b288bc00f602d2df0c
linuxlinux>= 4fdcfab5b5537c21891e22e65996d4d0dd8ab4ca < af9a8730ddb6a4b2edd779ccc0aceb994d616830af9a8730ddb6a4b2edd779ccc0aceb994d616830
linuxlinux>= 5.0.14 < 5.15.1
linuxlinux>= e22c11da0a8683d22011bbce18da493c079d67b3 < b6c8b3e31eb88c85094d848a0bd8b4bafe67e4d8b6c8b3e31eb88c85094d848a0bd8b4bafe67e4d8
linuxlinux_kernel< 4.19.3184.19.318
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.