PT-2024-34052 · Linux+6 · Linux Kernel+6

Syzbot

·

Published

2024-10-16

·

Updated

2025-10-08

·

CVE-2024-50218

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.61
Description: A vulnerability has been resolved in the Linux kernel. The issue is related to the ocfs2 file system, where passing a u64 value to ocfs2 truncate inline may cause an overflow. This is due to two reasons: the parameter value passed is greater than ocfs2 max inline data with xattr, and the start and end parameters of ocfs2 truncate inline are unsigned int. Syzbot reported a kernel BUG in ocfs2 truncate inline. A sanity check needs to be added for byte start and byte len before calling ocfs2 truncate inline() in ocfs2 remove inode range() to prevent this issue.
Recommendations: For Linux kernel versions prior to 6.6.61, update to version 6.6.61 or later to resolve the issue. As a temporary workaround, consider adding a sanity check for byte start and byte len in ocfs2 remove inode range() to prevent the overflow. Restrict access to the ocfs2 file system until the update is applied to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07909
CVE-2024-50218
DLA-4008-1
DLA-4075-1
DSA-5818-1
MGASA-2024-0368
MGASA-2024-0369
OESA-2024-2522
OESA-2024-2569
OESA-2024-2571
OESA-2024-2589
OESA-2025-1016
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2024_4376-1
OPENSUSE-SU-2025:14705-1
SUSE-SU-2024:4314-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4367-1
SUSE-SU-2024:4376-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:0035-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7276-1
USN-7277-1
USN-7288-1
USN-7288-2
USN-7289-1
USN-7289-2
USN-7289-3
USN-7289-4
USN-7291-1
USN-7293-1
USN-7294-1
USN-7294-2
USN-7294-3
USN-7294-4
USN-7295-1
USN-7305-1
USN-7308-1
USN-7310-1
USN-7331-1
USN-7388-1
USN-7389-1
USN-7390-1
USN-7393-1
USN-7401-1
USN-7413-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7458-1
USN-7468-1
USN-7523-1
USN-7524-1
USN-7539-1
USN-7540-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu