cbcvebase.
CVE-2024-49966
published 2024-10-21

CVE-2024-49966: In the Linux kernel, the following vulnerability has been resolved: ocfs2: cancel dqi_sync_work before freeing oinfo ocfs2_global_read_info() will initialize…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ocfs2: cancel dqi_sync_work before freeing oinfo ocfs2_global_read_info() will initialize and schedule dqi_sync_work at the end, if error occurs after successfully reading global quota, it will trigger the following warning with CONFIG_DEBUG_OBJECTS_* enabled: ODEBUG: free active (active state 0) object: 00000000d8b0ce28 object type: timer_list hint: qsync_work_fn+0x0/0x16c This reports that there is an active delayed work when freeing oinfo in error handling, so cancel dqi_sync_work first. BTW, return status instead of -1 when .read_file_info fails.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < fc5cc716dfbdc5fd5f373ff3b51358174cf88bfcfc5cc716dfbdc5fd5f373ff3b51358174cf88bfc
linuxlinux>= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < 89043e7ed63c7fc141e68ea5a79758ed24b6c69989043e7ed63c7fc141e68ea5a79758ed24b6c699
linuxlinux>= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < 14114d8148db07e7946fb06b56a50cfa425e26c714114d8148db07e7946fb06b56a50cfa425e26c7
linuxlinux>= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < 4173d1277c00baeedaaca76783e98b8fd0e3c08d4173d1277c00baeedaaca76783e98b8fd0e3c08d
linuxlinux>= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < bbf41277df8b33fbedf4750a9300c147e8f104ebbbf41277df8b33fbedf4750a9300c147e8f104eb
linuxlinux>= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < ef768020366f47d23f39c4f57bcb03af6d1e24b3ef768020366f47d23f39c4f57bcb03af6d1e24b3
linuxlinux>= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < a4346c04d055bf7e184c18a73dbd23b6a9811118a4346c04d055bf7e184c18a73dbd23b6a9811118
linuxlinux>= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < 0d707a33c84b371cb66120e198eed3374726ddd80d707a33c84b371cb66120e198eed3374726ddd8
linuxlinux>= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < 35fccce29feb3706f649726d410122dd81b92c1835fccce29feb3706f649726d410122dd81b92c18
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 2.6.29 < 4.19.3234.19.323
linuxlinux_kernel>= 4.20 < 5.4.2855.4.285
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.