cbcvebase.
CVE-2024-49965
published 2024-10-21

CVE-2024-49965: In the Linux kernel, the following vulnerability has been resolved: ocfs2: remove unreasonable unlock in ocfs2_read_blocks Patch series "Misc fixes for…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ocfs2: remove unreasonable unlock in ocfs2_read_blocks Patch series "Misc fixes for ocfs2_read_blocks", v5. This series contains 2 fixes for ocfs2_read_blocks(). The first patch fix the issue reported by syzbot, which detects bad unlock balance in ocfs2_read_blocks(). The second patch fixes an issue reported by Heming Zhao when reviewing above fix. This patch (of 2): There was a lock release before exiting, so remove the unreasonable unlock.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.157 < 4.154.15
linuxlinux>= 4.19.87 < 4.19.3234.19.323
linuxlinux>= 4.4.204 < 4.54.5
linuxlinux>= 4.9.204 < 4.104.10
linuxlinux>= 6c150df9c2e80b5cf86f5a0d98beb7390ad63bfc < 5245f109b4afb6595360d4c180d483a6d2009a595245f109b4afb6595360d4c180d483a6d2009a59
linuxlinux>= cf76c78595ca87548ca5e45c862ac9e0949c4687 < 9753bcb17b36c9add9b32c61766ddf8d2d1619119753bcb17b36c9add9b32c61766ddf8d2d161911
linuxlinux>= cf76c78595ca87548ca5e45c862ac9e0949c4687 < 3f1ca6ba5452d53c598a45d21267a2c0c221eef33f1ca6ba5452d53c598a45d21267a2c0c221eef3
linuxlinux>= cf76c78595ca87548ca5e45c862ac9e0949c4687 < f55a33fe0fb5274ef185fd61947cf142138958aff55a33fe0fb5274ef185fd61947cf142138958af
linuxlinux>= cf76c78595ca87548ca5e45c862ac9e0949c4687 < 81aba693b129e82e11bb54f569504d943d018de981aba693b129e82e11bb54f569504d943d018de9
linuxlinux>= cf76c78595ca87548ca5e45c862ac9e0949c4687 < 84543da867c967edffd5065fa910ebf56aaae49d84543da867c967edffd5065fa910ebf56aaae49d
linuxlinux>= cf76c78595ca87548ca5e45c862ac9e0949c4687 < df4f20fc3673cee11abf2c571987a95733cb638ddf4f20fc3673cee11abf2c571987a95733cb638d
linuxlinux>= cf76c78595ca87548ca5e45c862ac9e0949c4687 < 39a88623af3f1c686bf6db1e677ed865ffe6fccc39a88623af3f1c686bf6db1e677ed865ffe6fccc
linuxlinux>= cf76c78595ca87548ca5e45c862ac9e0949c4687 < c03a82b4a0c935774afa01fd6d128b444fd930a1c03a82b4a0c935774afa01fd6d128b444fd930a1
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.