PT-2024-33854 · Linux+8 · Linux Kernel+8

Luis Henriques

·

Published

2024-10-21

·

Updated

2026-05-26

·

CVE-2024-50014

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.10.0+
Description: A problem was fixed in the Linux kernel involving a bug in the ext4 fast-commit replay path. This issue can be triggered with fstest generic/629 on a filesystem with the fast-commit feature enabled, resulting in a kernel trace. The code attempts to lock an uninitialized spinlock sbi->s bdev wb lock in the ext4 check bdev write error() function. Moving the initialization of this spinlock to an earlier point in ext4 fill super() fixes the issue.
Recommendations: To resolve the issue, update the Linux kernel to a version that includes the fix for the uninitialized lock in the ext4 fast-commit replay path. As a temporary workaround, consider disabling the fast-commit feature on affected filesystems until a patch is available. Restrict access to the vulnerable ext4 check bdev write error() function to minimize the risk of exploitation.

Exploit

Fix

DoS

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2025-12647
AZL-51750
AZL-51788
BDU:2025-07976
BDU:2025-12364
CVE-2024-50014
DLA-4076-1
DSA-5860-1
INFSA-2025_6966
OESA-2024-2367
OESA-2024-2424
OESA-2024-2425
OESA-2024-2426
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2024_3983-1
OPENSUSE-SU-2024_3985-1
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2025:14705-1
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2024:3983-1
SUSE-SU-2024:3985-1
SUSE-SU-2024:4314-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7276-1
USN-7277-1
USN-7301-1
USN-7303-1
USN-7303-2
USN-7303-3
USN-7304-1
USN-7310-1
USN-7311-1
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7403-1
USN-7468-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu