cbcvebase.
CVE-2024-58001
published 2025-02-27

CVE-2024-58001: In the Linux kernel, the following vulnerability has been resolved: ocfs2: handle a symlink read error correctly Patch series "Convert ocfs2 to use folios"…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.3th percentile
In the Linux kernel, the following vulnerability has been resolved: ocfs2: handle a symlink read error correctly Patch series "Convert ocfs2 to use folios". Mark did a conversion of ocfs2 to use folios and sent it to me as a giant patch for review ;-) So I've redone it as individual patches, and credited Mark for the patches where his code is substantially the same. It's not a bad way to do it; his patch had some bugs and my patches had some bugs. Hopefully all our bugs were different from each other. And hopefully Mark likes all the changes I made to his code! This patch (of 23): If we can't read the buffer, be sure to unlock the page before returning.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= ea022dfb3c2a4680483b00eb2fecc9fc4f6091d1 < cd3e22b206189cbb4a94229002141e1529f83746cd3e22b206189cbb4a94229002141e1529f83746
linuxlinux>= ea022dfb3c2a4680483b00eb2fecc9fc4f6091d1 < afa8003f8db62e46c4b171cbf4cec2824148b4f7afa8003f8db62e46c4b171cbf4cec2824148b4f7
linuxlinux>= ea022dfb3c2a4680483b00eb2fecc9fc4f6091d1 < 8aee4184c5b79e486598c15aa80687c77f6f6e6e8aee4184c5b79e486598c15aa80687c77f6f6e6e
linuxlinux>= ea022dfb3c2a4680483b00eb2fecc9fc4f6091d1 < 6e143eb4ab83c24e7ad3e3d8e7daa241d9c383776e143eb4ab83c24e7ad3e3d8e7daa241d9c38377
linuxlinux>= ea022dfb3c2a4680483b00eb2fecc9fc4f6091d1 < b6833b38984d1e9f20dd80f9ec9050c10d687f30b6833b38984d1e9f20dd80f9ec9050c10d687f30
linuxlinux>= ea022dfb3c2a4680483b00eb2fecc9fc4f6091d1 < 52a326f93ceb9348264fddf7bab6e345db69e08c52a326f93ceb9348264fddf7bab6e345db69e08c
linuxlinux>= ea022dfb3c2a4680483b00eb2fecc9fc4f6091d1 < 5e3b3ec7c3cb5ba5629a766e4f0926db72cf0a1f5e3b3ec7c3cb5ba5629a766e4f0926db72cf0a1f
linuxlinux>= ea022dfb3c2a4680483b00eb2fecc9fc4f6091d1 < 2b4c2094da6d84e69b843dd3317902e977bf64bd2b4c2094da6d84e69b843dd3317902e977bf64bd
linuxlinux_kernel< 5.4.2915.4.291
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1296.1.129
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.36.13.3
linuxlinux_kernel>= 6.2 < 6.6.786.6.78
linuxlinux_kernel>= 6.7 < 6.12.146.12.14

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.