PT-2024-33774 · Linux+4 · Linux Kernel+4

Johannes Thumshirn

·

Published

2024-07-31

·

Updated

2026-05-26

·

CVE-2024-49932

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.10.0-rc7+
Description: The issue arises when the Linux kernel's btrfs filesystem is backed by a RAID stripe tree and readahead is performed on the relocation inode. This can lead to an ENOENT error due to preallocated extents not being mapped in the RST, causing the readahead to submit invalid reads to the device. As a result, an assertion occurs in the scatter-gather list code, leading to a kernel bug. The blk rq map sg function is involved in this process, and the error can cause the system to crash.
Recommendations: To resolve this issue, update the Linux kernel to a version newer than 6.10.0-rc7+. As a temporary workaround, consider disabling the readahead on relocation inode for btrfs filesystems to minimize the risk of exploitation.

Exploit

Fix

Assertion Failure

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17211
ALT-PU-2025-12647
AZL-52938
AZL-52979
BDU:2025-16127
CVE-2024-49932
ECHO-97AB-035A-C186
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2025:14705-1
USN-7276-1
USN-7277-1
USN-7310-1

Affected Products

Alt Linux
Debian
Linuxmint
Linux Kernel
Ubuntu