cbcvebase.
CVE-2024-50179
published 2024-11-08

CVE-2024-50179: In the Linux kernel, the following vulnerability has been resolved: ceph: remove the incorrect Fw reference check when dirtying pages When doing the direct-io…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ceph: remove the incorrect Fw reference check when dirtying pages When doing the direct-io reads it will also try to mark pages dirty, but for the read path it won't hold the Fw caps and there is case will it get the Fw reference.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 5dda377cf0a6bd43f64a3c1efb670d7c668e7b29 < c26c5ec832dd9e9dcd0a0a892a485c99889b68f0c26c5ec832dd9e9dcd0a0a892a485c99889b68f0
linuxlinux>= 5dda377cf0a6bd43f64a3c1efb670d7c668e7b29 < 126b567a2ef65fc38a71d832bf1216c56816f231126b567a2ef65fc38a71d832bf1216c56816f231
linuxlinux>= 5dda377cf0a6bd43f64a3c1efb670d7c668e7b29 < f55e003d261baa7c57d51ae5c8ec1f5c26a35c89f55e003d261baa7c57d51ae5c8ec1f5c26a35c89
linuxlinux>= 5dda377cf0a6bd43f64a3c1efb670d7c668e7b29 < f863bfd0a2c6c99011c62ea71ac04f8e78707da9f863bfd0a2c6c99011c62ea71ac04f8e78707da9
linuxlinux>= 5dda377cf0a6bd43f64a3c1efb670d7c668e7b29 < ea98284fc4fb05f276737d2043b02b62be5a8dfbea98284fc4fb05f276737d2043b02b62be5a8dfb
linuxlinux>= 5dda377cf0a6bd43f64a3c1efb670d7c668e7b29 < 11ab19d48ab877430eed0c7d83810970bbcbc4f611ab19d48ab877430eed0c7d83810970bbcbc4f6
linuxlinux>= 5dda377cf0a6bd43f64a3c1efb670d7c668e7b29 < 9d4f619153bab7fa59736462967821d6521a38cb9d4f619153bab7fa59736462967821d6521a38cb
linuxlinux>= 5dda377cf0a6bd43f64a3c1efb670d7c668e7b29 < 74b302ebad5b43ac17460fa58092d892a3cba6eb74b302ebad5b43ac17460fa58092d892a3cba6eb
linuxlinux>= 5dda377cf0a6bd43f64a3c1efb670d7c668e7b29 < c08dfb1b49492c09cf13838c71897493ea3b424ec08dfb1b49492c09cf13838c71897493ea3b424e
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 0 < 4.4.0-276.3104.4.0-276.310
linuxlinux_kernel>= 0 < 4.15.0-245.2574.15.0-245.257
linuxlinux_kernel>= 4.2 < 4.19.3234.19.323
linuxlinux_kernel>= 4.20 < 5.4.2855.4.285
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.