PT-2024-33797 · Linux+2 · Linux Kernel+2

Published

2024-08-20

·

Updated

2025-02-28

·

CVE-2024-49956

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A double destroy workqueue error has been identified in the Linux kernel, specifically in the gfs2 module. This issue occurs when gfs2 fill super() fails, leading to destroy workqueue() being called twice on the same work queue. The problem can be resolved by setting the work queue pointer to NULL after the first destroy workqueue() call and checking for a NULL pointer before attempting to destroy the work queue again.
Recommendations: To fix this issue, set the work queue pointer to NULL after the first destroy workqueue() call and check for a NULL pointer before attempting to destroy the work queue again. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16130
CVE-2024-49956
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2025:14705-1
USN-7276-1
USN-7277-1
USN-7310-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu