cbcvebase.
CVE-2024-49883
published 2024-10-21

CVE-2024-49883: In the Linux kernel, the following vulnerability has been resolved: ext4: aovid use-after-free in ext4_ext_insert_extent() As Ojaswin mentioned in Link, in…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.1th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: aovid use-after-free in ext4_ext_insert_extent() As Ojaswin mentioned in Link, in ext4_ext_insert_extent(), if the path is reallocated in ext4_ext_create_new_leaf(), we'll use the stale path and cause UAF. Below is a sample trace with dummy values: ext4_ext_insert_extent path = *ppath = 2000 ext4_ext_create_new_leaf(ppath) ext4_find_extent(ppath) path = *ppath = 2000 if (depth > path[0].p_maxdepth) kfree(path = 2000); *ppath = path = NULL; path = kcalloc() = 3000 *ppath = 3000; return path; /* here path is still 2000, UAF! */ eh = path[depth].p_hdr BUG: KASAN: slab-use-after-free in ext4_ext_insert_extent+0x26d4/0x3330 Read of size 8 at addr ffff8881027bf7d0 by task kworker/u36:1/179 CPU: 3 UID: 0 PID: 179 Comm: kworker/u6:1 Not tainted 6.11.0-rc2-dirty #866 Call Trace: ext4_ext_insert_extent+0x26d4/0x3330 ext4_ext_map_blocks+0xe22/0x2d40 ext4_map_blocks+0x71e/0x1700 ext4_do_writepages+0x1290/0x2800 [...] Allocated by task 179: ext4_find_extent+0x81c/0x1f70 ext4_ext_map_blocks+0x146/0x2d40 ext4_map_blocks+0x71e/0x1700 ext4_do_writepages+0x1290/0x2800 ext4_writepages+0x26d/0x4e0 do_writepages+0x175/0x700 [...] Freed by task 179: kfree+0xcb/0x240 ext4_find_extent+0x7c0/0x1f70 ext4_ext_insert_extent+0xa26/0x3330 ext4_ext_map_blocks+0xe22/0x2d40 ext4_map_blocks+0x71e/0x1700 ext4_do_writepages+0x1290/0x2800 ext4_writepages+0x26d/0x4e0 do_writepages+0x175/0x700 [...] So use *ppath to update the path to avoid the above problem.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 10809df84a4d868db61af621bae3658494165279 < e17ebe4fdd7665c93ae9459ba40fcdfb76769ac1e17ebe4fdd7665c93ae9459ba40fcdfb76769ac1
linuxlinux>= 10809df84a4d868db61af621bae3658494165279 < 975ca06f3fd154c5f7742083e7b2574c57d1c0c3975ca06f3fd154c5f7742083e7b2574c57d1c0c3
linuxlinux>= 10809df84a4d868db61af621bae3658494165279 < 5e811066c5ab709b070659197dccfb80ab650ddd5e811066c5ab709b070659197dccfb80ab650ddd
linuxlinux>= 10809df84a4d868db61af621bae3658494165279 < 9df59009dfc6d9fc1bd9ddf6c5ab6e56d6ed887a9df59009dfc6d9fc1bd9ddf6c5ab6e56d6ed887a
linuxlinux>= 10809df84a4d868db61af621bae3658494165279 < 51db04892a993cace63415be99848970a0f15ef251db04892a993cace63415be99848970a0f15ef2
linuxlinux>= 10809df84a4d868db61af621bae3658494165279 < 8162ee5d94b8c0351be0a9321be134872a7654a18162ee5d94b8c0351be0a9321be134872a7654a1
linuxlinux>= 10809df84a4d868db61af621bae3658494165279 < beb7b66fb489041c50c6473100b383f7a51648fcbeb7b66fb489041c50c6473100b383f7a51648fc
linuxlinux>= 10809df84a4d868db61af621bae3658494165279 < bfed082ce4b1ce6349b05c09a0fa4f3da35ecb1bbfed082ce4b1ce6349b05c09a0fa4f3da35ecb1b
linuxlinux>= 10809df84a4d868db61af621bae3658494165279 < a164f3a432aae62ca23d03e6d926b122ee5b860da164f3a432aae62ca23d03e6d926b122ee5b860d
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 0 < 4.4.0-271.3054.4.0-271.305
linuxlinux_kernel>= 0 < 4.15.0-240.2524.15.0-240.252
linuxlinux_kernel>= 3.18 < 4.19.3234.19.323
linuxlinux_kernel>= 4.20 < 5.4.2855.4.285

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.