PT-2024-33728 · Linux+2 · Linux Kernel+2

Syzbot

·

Published

2024-09-10

·

Updated

2026-04-20

·

CVE-2024-49887

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.11.0-rc6-syzkaller-00363-g89f5e14d05b4
Description: A vulnerability in the Linux kernel has been resolved, specifically in the f2fs filesystem. The issue occurs when a no free segment fault is injected into f2fs, causing the system to panic. The root cause of the problem is that the system should not panic when this fault is injected. The vulnerability is related to the get new segment function in fs/f2fs/segment.c and the new curseg function in the same file. The estimated number of potentially affected devices is not specified.
Recommendations: To resolve the issue, update the Linux kernel to a version newer than 6.11.0-rc6-syzkaller-00363-g89f5e14d05b4. As a temporary workaround, consider disabling the f2fs filesystem until a patch is available. Restrict access to the vulnerable f2fs module to minimize the risk of exploitation. Avoid using the f2fs fallocate function in the affected kernel version until the issue is resolved.

Exploit

Fix

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13851
CVE-2024-49887
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2025:14705-1
USN-7276-1
USN-7277-1
USN-7310-1
USN-7651-1
USN-7651-2
USN-7651-3
USN-7651-4
USN-7651-5
USN-7651-6
USN-7652-1
USN-7653-1
USN-7737-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu