PT-2024-10457 · Linux+5 · Linux Kernel+5

Wang Yong

·

Published

2024-07-30

·

Updated

2025-02-03

·

CVE-2024-42115

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.43
Description A vulnerability in the Linux kernel's jffs2 file system has been resolved. The issue was related to a potential illegal address access in the jffs2 free inode function. During stress testing, abnormal printouts were found, indicating a kernel paging request error at a virtual address. The error was caused by the destroy inode process being triggered in the iget locked function, which released the inode and consequently did not initialize the target member of the inode. The fix method is to set the target to NULL in the jffs2 i init once function.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.43 or later. As a temporary workaround, consider disabling the jffs2 file system until a patch is available. However, since the fix is to set the target to NULL in the jffs2 i init once function, applying this patch or updating to a version that includes this fix is the recommended resolution.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00997
CVE-2024-42115
DLA-4008-1
DSA-5747-1
MGASA-2024-0277
MGASA-2024-0278
OESA-2024-1960
OESA-2024-1962
OESA-2024-1963
OESA-2024-1964
OESA-2024-2258
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
SUSE-SU-2024:3190-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:3483-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-7003-1
USN-7003-2
USN-7003-3
USN-7003-4
USN-7003-5
USN-7006-1
USN-7007-1
USN-7007-2
USN-7007-3
USN-7009-1
USN-7009-2
USN-7019-1
USN-7089-1
USN-7089-2
USN-7089-3
USN-7089-4
USN-7089-5
USN-7089-6
USN-7089-7
USN-7090-1
USN-7095-1
USN-7156-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu