PT-2024-27213 · Linux+7 · Linux Kernel+7
Syzbot
·
Published
2024-03-19
·
Updated
2026-05-26
·
CVE-2024-36923
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue arises when an iget fails due to the inability to retrieve information from the server, resulting in a partially initialized inode structure. Upon eviction, references are made to uninitialized structures, such as fscache cookies. A patch has been applied to check for a bad inode before clearing the inode from the cache, as a bad inode should not have any associated state that needs to be written back.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Use of Uninitialized Resource
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu