CVE-2024-50230

HIGH EPSS 18.5%
Published Nov 9, 20241y ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Nov 9, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix kernel bug due to missing clearing of checked flag Syzbot reported that in directory operations after nilfs2 detects filesystem corruption and degrades to read-only, __block_write_begin_int(), which is called to prepare block writes, may fail the BUG_ON check for accesses exceeding the folio/page size, triggering a kernel bug. This was found to be because the "checked" flag of a page/folio was not cleared when it was discarded by nilfs2's own routine, which causes the sanity check of directory entries to be skipped when the directory page/folio is reloaded. So, fix that. This was necessary when the use of nilfs2's own page discard routine was applied to more than just metadata files.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
18.5% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-787 Out-of-bounds Write Memory Safety

Affected Products 12

VendorProductVersionRange
linuxlinux_kernel*≥3.10  –  <4.19.323
linuxlinux_kernel*≥4.20  –  <5.4.285
linuxlinux_kernel*≥5.5  –  <5.10.229
linuxlinux_kernel*≥5.11  –  <5.15.171
linuxlinux_kernel*≥5.16  –  <6.1.116
linuxlinux_kernel*≥6.2  –  <6.6.60
linuxlinux_kernel*≥6.7  –  <6.11.7
linuxlinux_kernel6.12any
linuxlinux_kernel6.12any
linuxlinux_kernel6.12any
linuxlinux_kernel6.12any
linuxlinux_kernel6.12any

References 10

  • git.kernel.org https://git.kernel.org/stable/c/41e192ad2779cae0102879612dfe46726e4396aa
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/56c6171932a7fb267ac6cb4ff8759b93ee1d0e2e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/64afad73e4623308d8943645e5631f2c7a2d7971
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/994b2fa13a6c9cf3feca93090a9c337d48e3d60d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/aa0cee46c5d3fd9a39575a4c8a4f65f25f095b89
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cd0cdb51b15203fa27d4b714be83b7dfffa0b752
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f05dbebb8ee34882505d53d83af7d18f28a49248
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f2f1fa446676c21edb777e6d2bc4fa8f956fab68
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/41e192ad2779cae0102879612dfe46726e4396aa
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/56c6171932a7fb267ac6cb4ff8759b93ee1d0e2e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/64afad73e4623308d8943645e5631f2c7a2d7971
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/994b2fa13a6c9cf3feca93090a9c337d48e3d60d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/aa0cee46c5d3fd9a39575a4c8a4f65f25f095b89
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cd0cdb51b15203fa27d4b714be83b7dfffa0b752
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f05dbebb8ee34882505d53d83af7d18f28a49248
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f2f1fa446676c21edb777e6d2bc4fa8f956fab68
    Patch