PT-2024-21463 · Linux+5 · Linux Kernel+5
Syzbot
·
Published
2024-02-07
·
Updated
2025-03-13
·
CVE-2024-26685
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the
end buffer async write() function, which handles the completion of block device writes. According to a syzbot report, this function may detect an abnormal condition of the buffer async write flag and cause a BUG ON failure when using nilfs2. The async write flag is used as a marker to resolve double list insertion of dirty blocks in nilfs lookup dirty data buffers() and nilfs lookup node buffers(). However, introducing async write for segment summary and super root blocks that share buffers with the backing device was irrelevant and redundant, leading to the possibility of a BUG ON check failure in end buffer async write() if independent writebacks of the backing device occurred in parallel.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu