cbcvebase.
CVE-2024-46781
published 2024-09-18

CVE-2024-46781: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix missing cleanup on rollforward recovery error In an error injection test of a…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.5th percentile
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix missing cleanup on rollforward recovery error In an error injection test of a routine for mount-time recovery, KASAN found a use-after-free bug. It turned out that if data recovery was performed using partial logs created by dsync writes, but an error occurred before starting the log writer to create a recovered checkpoint, the inodes whose data had been recovered were left in the ns_dirty_files list of the nilfs object and were not freed. Fix this issue by cleaning up inodes that have read the recovery data if the recovery routine fails midway before the log writer starts.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 0f3e1c7f23f8a6f8224fa1d275381f6d9279ad4b < 35a9a7a7d94662146396199b0cfd95f9517cdd1435a9a7a7d94662146396199b0cfd95f9517cdd14
linuxlinux>= 0f3e1c7f23f8a6f8224fa1d275381f6d9279ad4b < da02f9eb333333b2e4f25d2a14967cff785ac82eda02f9eb333333b2e4f25d2a14967cff785ac82e
linuxlinux>= 0f3e1c7f23f8a6f8224fa1d275381f6d9279ad4b < 07e4dc2fe000ab008bcfe90be4324ef56b5b435507e4dc2fe000ab008bcfe90be4324ef56b5b4355
linuxlinux>= 0f3e1c7f23f8a6f8224fa1d275381f6d9279ad4b < 8e2d1e9d93c4ec51354229361ac3373058529ec48e2d1e9d93c4ec51354229361ac3373058529ec4
linuxlinux>= 0f3e1c7f23f8a6f8224fa1d275381f6d9279ad4b < ca92c4bff2833cb30d493b935168d6cccd5c805dca92c4bff2833cb30d493b935168d6cccd5c805d
linuxlinux>= 0f3e1c7f23f8a6f8224fa1d275381f6d9279ad4b < 9d8c3a585d564d776ee60d4aabec59b404be74039d8c3a585d564d776ee60d4aabec59b404be7403
linuxlinux>= 0f3e1c7f23f8a6f8224fa1d275381f6d9279ad4b < 1cf1f7e8cd47244fa947d357ef1f642d91e219a31cf1f7e8cd47244fa947d357ef1f642d91e219a3
linuxlinux>= 0f3e1c7f23f8a6f8224fa1d275381f6d9279ad4b < 5787fcaab9eb5930f5378d6a1dd03d916d1466225787fcaab9eb5930f5378d6a1dd03d916d146622
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 2.6.30 < 4.19.3224.19.322

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.