cbcvebase.
CVE-2024-50230
published 2024-11-09

CVE-2024-50230: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix kernel bug due to missing clearing of checked flag Syzbot reported that in…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.0th percentile
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix kernel bug due to missing clearing of checked flag Syzbot reported that in directory operations after nilfs2 detects filesystem corruption and degrades to read-only, __block_write_begin_int(), which is called to prepare block writes, may fail the BUG_ON check for accesses exceeding the folio/page size, triggering a kernel bug. This was found to be because the "checked" flag of a page/folio was not cleared when it was discarded by nilfs2's own routine, which causes the sanity check of directory entries to be skipped when the directory page/folio is reloaded. So, fix that. This was necessary when the use of nilfs2's own page discard routine was applied to more than just metadata files.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= 8c26c4e2694a163d525976e804d81cd955bbb40c < 994b2fa13a6c9cf3feca93090a9c337d48e3d60d994b2fa13a6c9cf3feca93090a9c337d48e3d60d
linuxlinux>= 8c26c4e2694a163d525976e804d81cd955bbb40c < 64afad73e4623308d8943645e5631f2c7a2d797164afad73e4623308d8943645e5631f2c7a2d7971
linuxlinux>= 8c26c4e2694a163d525976e804d81cd955bbb40c < aa0cee46c5d3fd9a39575a4c8a4f65f25f095b89aa0cee46c5d3fd9a39575a4c8a4f65f25f095b89
linuxlinux>= 8c26c4e2694a163d525976e804d81cd955bbb40c < f05dbebb8ee34882505d53d83af7d18f28a49248f05dbebb8ee34882505d53d83af7d18f28a49248
linuxlinux>= 8c26c4e2694a163d525976e804d81cd955bbb40c < cd0cdb51b15203fa27d4b714be83b7dfffa0b752cd0cdb51b15203fa27d4b714be83b7dfffa0b752
linuxlinux>= 8c26c4e2694a163d525976e804d81cd955bbb40c < f2f1fa446676c21edb777e6d2bc4fa8f956fab68f2f1fa446676c21edb777e6d2bc4fa8f956fab68
linuxlinux>= 8c26c4e2694a163d525976e804d81cd955bbb40c < 56c6171932a7fb267ac6cb4ff8759b93ee1d0e2e56c6171932a7fb267ac6cb4ff8759b93ee1d0e2e
linuxlinux>= 8c26c4e2694a163d525976e804d81cd955bbb40c < 41e192ad2779cae0102879612dfe46726e4396aa41e192ad2779cae0102879612dfe46726e4396aa
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.7-16.11.7-1
linuxlinux_kernel>= 0 < 6.11.7-16.11.7-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 3.10 < 4.19.3234.19.323
linuxlinux_kernel>= 4.20 < 5.4.2855.4.285
linuxlinux_kernel>= 5.11 < 5.15.1715.15.171
linuxlinux_kernel>= 5.16 < 6.1.1166.1.116
linuxlinux_kernel>= 5.5 < 5.10.2295.10.229

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.