CVE-2024-47726Resource Injection in Linux

CWE-99Resource Injection62 documents7 sources
Severity
6.5MEDIUMNVD
OSV8.8OSV7.8OSV5.5
EPSS
0.2%
top 64.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateJun 26

Description

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to wait dio completion It should wait all existing dio write IOs before block removal, otherwise, previous direct write IO may overwrite data in the block which may be reused by other inode.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages10 packages

Patches

🔴Vulnerability Details

30
OSV
linux-xilinx-zynqmp vulnerabilities2025-06-26
OSV
linux-hwe-5.15 vulnerabilities2025-06-24
OSV
linux-aws-5.15 vulnerabilities2025-05-29
OSV
linux-aws, linux-intel-iotg-5.15, linux-nvidia-tegra-igx, linux-raspi vulnerabilities2025-05-28
OSV
linux-aws-fips vulnerabilities2025-05-27

📋Vendor Advisories

31
Ubuntu
Linux kernel (Xilinx ZynqMP) vulnerabilities2025-06-26
Ubuntu
Linux kernel (HWE) vulnerabilities2025-06-24
Ubuntu
Linux kernel (AWS) vulnerabilities2025-05-29
Ubuntu
Linux kernel vulnerabilities2025-05-28
Ubuntu
Linux kernel (AWS FIPS) vulnerabilities2025-05-27