cbcvebase.
CVE-2024-50273
published 2024-11-19

CVE-2024-50273: In the Linux kernel, the following vulnerability has been resolved: btrfs: reinitialize delayed ref list after deleting it from the list At…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.4th percentile
In the Linux kernel, the following vulnerability has been resolved: btrfs: reinitialize delayed ref list after deleting it from the list At insert_delayed_ref() if we need to update the action of an existing ref to BTRFS_DROP_DELAYED_REF, we delete the ref from its ref head's ref_add_list using list_del(), which leaves the ref's add_list member not reinitialized, as list_del() sets the next and prev members of the list to LIST_POISON1 and LIST_POISON2, respectively. If later we end up calling drop_delayed_ref() against the ref, which can happen during merging or when destroying delayed refs due to a transaction abort, we can trigger a crash since at drop_delayed_ref() we call list_empty() against the ref's add_list, which returns false since the list was not reinitialized after the list_del() and as a consequence we call list_del() again at drop_delayed_ref(). This results in an invalid list access since the next and prev members are set to poison pointers, resulting in a splat if CONFIG_LIST_HARDENED and CONFIG_DEBUG_LIST are set or invalid poison pointer dereferences otherwise. So fix this by deleting from the list with list_del_init() instead.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= 1d57ee941692d0cc928526e21a1557b2ae3e11db < 2fd0948a483e9cb2d669c7199bc620a21c97673d2fd0948a483e9cb2d669c7199bc620a21c97673d
linuxlinux>= 1d57ee941692d0cc928526e21a1557b2ae3e11db < 93c5b8decc0ef39ba84f4211d2db6da0a4aefbeb93c5b8decc0ef39ba84f4211d2db6da0a4aefbeb
linuxlinux>= 1d57ee941692d0cc928526e21a1557b2ae3e11db < bf0b0c6d159767c0d1c21f793950d78486690ee0bf0b0c6d159767c0d1c21f793950d78486690ee0
linuxlinux>= 1d57ee941692d0cc928526e21a1557b2ae3e11db < c24fa427fc0ae827b2a3a07f13738cbf82c3f851c24fa427fc0ae827b2a3a07f13738cbf82c3f851
linuxlinux>= 1d57ee941692d0cc928526e21a1557b2ae3e11db < 2cb1a73d1d44a1c11b0ee5eeced765dd80ec48e62cb1a73d1d44a1c11b0ee5eeced765dd80ec48e6
linuxlinux>= 1d57ee941692d0cc928526e21a1557b2ae3e11db < f04be6d68f715c1473a8422fc0460f57b5e99931f04be6d68f715c1473a8422fc0460f57b5e99931
linuxlinux>= 1d57ee941692d0cc928526e21a1557b2ae3e11db < 50a3933760b427759afdd23156a7280a19357a9250a3933760b427759afdd23156a7280a19357a92
linuxlinux>= 1d57ee941692d0cc928526e21a1557b2ae3e11db < c9a75ec45f1111ef530ab186c2a7684d0a0c9245c9a75ec45f1111ef530ab186c2a7684d0a0c9245
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.