CVE-2024-49883Use After Free in Linux

CWE-416Use After Free90 documents8 sources
Severity
7.8HIGHNVD
OSV8.8OSV6.7OSV6.3OSV5.5OSV4.7
EPSS
0.0%
top 98.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateAug 18

Description

In the Linux kernel, the following vulnerability has been resolved: ext4: aovid use-after-free in ext4_ext_insert_extent() As Ojaswin mentioned in Link, in ext4_ext_insert_extent(), if the path is reallocated in ext4_ext_create_new_leaf(), we'll use the stale path and cause UAF. Below is a sample trace with dummy values: ext4_ext_insert_extent path = *ppath = 2000 ext4_ext_create_new_leaf(ppath) ext4_find_extent(ppath) path = *ppath = 2000 if (depth > path[0].p_maxdepth) kfree(path = 2000); *

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages14 packages

Patches

🔴Vulnerability Details

43
OSV
linux-oracle vulnerabilities2025-08-13
OSV
linux-azure vulnerabilities2025-08-05
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm vulnerabilities2025-08-05
OSV
linux-oracle vulnerabilities2025-08-05
OSV
linux-aws-fips, linux-azure-fips, linux-fips, linux-gcp-fips vulnerabilities2025-08-05

📋Vendor Advisories

46
Ubuntu
Kernel Live Patch Security Notice2025-08-18
CISA ICS
Siemens Third-Party Components in SINEC OS2025-08-14
Ubuntu
Linux kernel (Oracle) vulnerabilities2025-08-13
Ubuntu
Linux kernel (Oracle) vulnerabilities2025-08-05
Ubuntu
Linux kernel vulnerabilities2025-08-05
CVE-2024-49883 — Use After Free in Linux | cvebase