PT-2024-36870 · Linux+3 · Linux Kernel+3

Piergiorgio Sartor

·

Published

2024-11-23

·

Updated

2026-05-26

·

CVE-2024-56565

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.74
Description A vulnerability in the Linux kernel has been resolved, related to the f2fs file system. The issue occurs when creating a snapshot on an LVM device, which updates the discard max bytes to zero, causing a panic when submit discard cmd() is called. The root cause is that submit discard cmd() passes a zero value to blkdev issue discard(), resulting in a NULL bio pointer. The vulnerability can be reproduced with a specific test case involving the creation of an LVM device, mounting an f2fs file system, and creating a snapshot.
Recommendations For Linux kernel versions prior to 6.6.74, update to version 6.6.74 or later to resolve the issue. As a temporary workaround, consider disabling the creation of snapshots on LVM devices to minimize the risk of exploitation. Restrict access to the f2fs file system to prevent potential attacks. Avoid using the submit discard cmd() function until the issue is resolved.

Exploit

Fix

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2026-04525
CVE-2024-56565
ECHO-0E0B-3A4D-0CED
MGASA-2025-0030
MGASA-2025-0032
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu