cbcvebase.
CVE-2024-49960
published 2024-10-21

CVE-2024-49960: In the Linux kernel, the following vulnerability has been resolved: ext4: fix timer use-after-free on failed mount Syzbot has found an ODEBUG bug in…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: fix timer use-after-free on failed mount Syzbot has found an ODEBUG bug in ext4_fill_super The del_timer_sync function cancels the s_err_report timer, which reminds about filesystem errors daily. We should guarantee the timer is no longer active before kfree(sbi). When filesystem mounting fails, the flow goes to failed_mount3, where an error occurs when ext4_stop_mmpd is called, causing a read I/O failure. This triggers the ext4_handle_error function that ultimately re-arms the timer, leaving the s_err_report timer active before kfree(sbi) is called. Fix the issue by canceling the s_err_report timer after calling ext4_stop_mmpd.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 5.10.51 < 5.10.2375.10.237
linuxlinux>= 5.12.18 < 5.135.13
linuxlinux>= 5.13.3 < 5.145.14
linuxlinux>= 5e4f5138bd8522ebe231a137682d3857209a2c07 < 7aac0c17a8cdf4a3236991c1e60435c6a984076c7aac0c17a8cdf4a3236991c1e60435c6a984076c
linuxlinux>= 618f003199c6188e01472b03cdbba227f1dc5f24 < 22e9b83f0f33bc5a7a3181769d1dccbf021f5b0422e9b83f0f33bc5a7a3181769d1dccbf021f5b04
linuxlinux>= 618f003199c6188e01472b03cdbba227f1dc5f24 < cf3196e5e2f36cd80dab91ffae402e13935724bccf3196e5e2f36cd80dab91ffae402e13935724bc
linuxlinux>= 618f003199c6188e01472b03cdbba227f1dc5f24 < 9203817ba46ebba7c865c8de2aba399537b6e8919203817ba46ebba7c865c8de2aba399537b6e891
linuxlinux>= 618f003199c6188e01472b03cdbba227f1dc5f24 < fa78fb51d396f4f2f80f8e96a3b1516f394258befa78fb51d396f4f2f80f8e96a3b1516f394258be
linuxlinux>= 618f003199c6188e01472b03cdbba227f1dc5f24 < b85569585d0154d4db1e4f9e3e6a4731d407feb0b85569585d0154d4db1e4f9e3e6a4731d407feb0
linuxlinux>= 618f003199c6188e01472b03cdbba227f1dc5f24 < 0ce160c5bdb67081a62293028dc85758a8efb22a0ce160c5bdb67081a62293028dc85758a8efb22a
linuxlinux_kernel< 5.10.2375.10.237
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.