cbcvebase.
CVE-2024-42273
published 2024-08-17

CVE-2024-42273: In the Linux kernel, the following vulnerability has been resolved: f2fs: assign CURSEG_ALL_DATA_ATGC if blkaddr is valid mkdir /mnt/test/comp f2fs_io setflags…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.9th percentile
In the Linux kernel, the following vulnerability has been resolved: f2fs: assign CURSEG_ALL_DATA_ATGC if blkaddr is valid mkdir /mnt/test/comp f2fs_io setflags compression /mnt/test/comp dd if=/dev/zero of=/mnt/test/comp/testfile bs=16k count=1 truncate --size 13 /mnt/test/comp/testfile In the above scenario, we can get a BUG_ON. kernel BUG at fs/f2fs/segment.c:3589! Call Trace: do_write_page+0x78/0x390 [f2fs] f2fs_outplace_write_data+0x62/0xb0 [f2fs] f2fs_do_write_data_page+0x275/0x740 [f2fs] f2fs_write_single_data_page+0x1dc/0x8f0 [f2fs] f2fs_write_multi_pages+0x1e5/0xae0 [f2fs] f2fs_write_cache_pages+0xab1/0xc60 [f2fs] f2fs_write_data_pages+0x2d8/0x330 [f2fs] do_writepages+0xcf/0x270 __writeback_single_inode+0x44/0x350 writeback_sb_inodes+0x242/0x530 __writeback_inodes_wb+0x54/0xf0 wb_writeback+0x192/0x310 wb_workfn+0x30d/0x400 The reason is we gave CURSEG_ALL_DATA_ATGC to COMPR_ADDR where the page was set the gcing flag by set_cluster_dirty().

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 417b8a91f4e8831cadaf85c3f15c6991c1f54dde < 4239571c5db46a42f723b8fa8394039187c344394239571c5db46a42f723b8fa8394039187c34439
linuxlinux>= 4961acdd65c956e97c1a000c82d91a8c1cdbe44b < 0cd106612396656d6f1ca17ef192c6759bb607910cd106612396656d6f1ca17ef192c6759bb60791
linuxlinux>= 4961acdd65c956e97c1a000c82d91a8c1cdbe44b < 8cb1f4080dd91c6e6b01dbea013a3f42341cb6a18cb1f4080dd91c6e6b01dbea013a3f42341cb6a1
linuxlinux>= 5.15.149 < 5.165.16
linuxlinux>= 6.1.77 < 6.1.1046.1.104
linuxlinux>= 6.6.16 < 6.6.456.6.45
linuxlinux>= 6.7.4 < 6.86.8
linuxlinux>= 7c972c89457511007dfc933814c06786905e515c < 5fd057160ab240dd816ae09b625395d54c297de15fd057160ab240dd816ae09b625395d54c297de1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.4-16.10.4-1
linuxlinux_kernel>= 0 < 6.10.4-16.10.4-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.15.149 < 5.165.16
linuxlinux_kernel>= 6.1.77 < 6.1.1046.1.104
linuxlinux_kernel>= 6.6.16 < 6.6.456.6.45
linuxlinux_kernel>= 6.7.4 < 6.10.46.10.4
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.