cbcvebase.
CVE-2024-47757
published 2024-10-21

CVE-2024-47757: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential oob read in nilfs_btree_check_delete() The function…

PriorityP432high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.24%
15.1th percentile
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential oob read in nilfs_btree_check_delete() The function nilfs_btree_check_delete(), which checks whether degeneration to direct mapping occurs before deleting a b-tree entry, causes memory access outside the block buffer when retrieving the maximum key if the root node has no entries. This does not usually happen because b-tree mappings with 0 child nodes are never created by mkfs.nilfs2 or nilfs2 itself. However, it can happen if the b-tree root node read from a device is configured that way, so fix this potential issue by adding a check for that case.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 17c76b0104e4a6513983777e1a17e0297a12b0c4 < f3a9859767c7aea758976f5523903d247e585129f3a9859767c7aea758976f5523903d247e585129
linuxlinux>= 17c76b0104e4a6513983777e1a17e0297a12b0c4 < ed76d381dae125b81d09934e365391a656249da8ed76d381dae125b81d09934e365391a656249da8
linuxlinux>= 17c76b0104e4a6513983777e1a17e0297a12b0c4 < d20674f31626e0596ae4c1d9401dfb6739b81b58d20674f31626e0596ae4c1d9401dfb6739b81b58
linuxlinux>= 17c76b0104e4a6513983777e1a17e0297a12b0c4 < c4f8554996e8ada3be872dfb8f60e93bcf15fb27c4f8554996e8ada3be872dfb8f60e93bcf15fb27
linuxlinux>= 17c76b0104e4a6513983777e1a17e0297a12b0c4 < a8abfda768b9f33630cfbc4af6c4214f1e5681b0a8abfda768b9f33630cfbc4af6c4214f1e5681b0
linuxlinux>= 17c76b0104e4a6513983777e1a17e0297a12b0c4 < 257f9e5185eb6de83377caea686c306e22e871f2257f9e5185eb6de83377caea686c306e22e871f2
linuxlinux>= 17c76b0104e4a6513983777e1a17e0297a12b0c4 < a33e967b681e088a125b979975c93e3453e686cda33e967b681e088a125b979975c93e3453e686cd
linuxlinux>= 17c76b0104e4a6513983777e1a17e0297a12b0c4 < c4cbcc64bb31e67e02940ce060cc77f7180564cfc4cbcc64bb31e67e02940ce060cc77f7180564cf
linuxlinux>= 17c76b0104e4a6513983777e1a17e0297a12b0c4 < f9c96351aa6718b42a9f42eaf7adce0356bdb5e8f9c96351aa6718b42a9f42eaf7adce0356bdb5e8
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 2.6.30 < 5.10.2275.10.227
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113
linuxlinux_kernel>= 6.11 < 6.11.26.11.2
linuxlinux_kernel>= 6.2 < 6.6.546.6.54

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.