cbcvebase.
CVE-2024-46752
published 2024-09-18

CVE-2024-46752: In the Linux kernel, the following vulnerability has been resolved: btrfs: replace BUG_ON() with error handling at update_ref_for_cow() Instead of a BUG_ON()…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.0th percentile
In the Linux kernel, the following vulnerability has been resolved: btrfs: replace BUG_ON() with error handling at update_ref_for_cow() Instead of a BUG_ON() just return an error, log an error message and abort the transaction in case we find an extent buffer belonging to the relocation tree that doesn't have the full backref flag set. This is unexpected and should never happen (save for bugs or a potential bad memory).

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 5d4f98a28c7d334091c1b7744f48a1acdd2a4ae0 < b50857b96429a09fd3beed9f7f21b7bb7c433688b50857b96429a09fd3beed9f7f21b7bb7c433688
linuxlinux>= 5d4f98a28c7d334091c1b7744f48a1acdd2a4ae0 < 0fbac73a97286a7ec72229cb9b42d760a2c717ac0fbac73a97286a7ec72229cb9b42d760a2c717ac
linuxlinux>= 5d4f98a28c7d334091c1b7744f48a1acdd2a4ae0 < 41a0f85e268d72fe04f731b8ceea4748c2d6549141a0f85e268d72fe04f731b8ceea4748c2d65491
linuxlinux>= 5d4f98a28c7d334091c1b7744f48a1acdd2a4ae0 < f895db00c65e5d77c437cce946da9ec29dcdf563f895db00c65e5d77c437cce946da9ec29dcdf563
linuxlinux>= 5d4f98a28c7d334091c1b7744f48a1acdd2a4ae0 < b56329a782314fde5b61058e2a25097af7ccb675b56329a782314fde5b61058e2a25097af7ccb675
linuxlinux_kernel< 5.15.1675.15.167
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.16 < 6.1.1106.1.110
linuxlinux_kernel>= 6.2 < 6.6.516.6.51
linuxlinux_kernel>= 6.7 < 6.10.106.10.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.