PT-2024-7321 · Linux+3 · Linux Kernel+3

Chenyuan Yang

·

Published

2024-01-31

·

Updated

2024-11-05

·

CVE-2024-26727

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The vulnerability is related to the btrfs component of the Linux kernel and is caused by an assertion failure during subvolume creation. This can lead to a denial of service. The issue arises when the btrfs get new fs root() function is triggered after inserting a root item for a newly created subvolume, and an anonymous device number has already been assigned to the subvolume. The btrfs get root ref() function is involved in this process. To fix the issue, the assertion is removed, and the preallocated anonymous device number is freed.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08676
CVE-2024-26727
DLA-3842-1
DSA-5658-1
DSA-5681-1
OPENSUSE-SU-2024_1490-1
OPENSUSE-SU-2024_1641-1
OPENSUSE-SU-2024_1659-1
OPENSUSE-SU-2024_1663-1
SUSE-SU-2024:1490-1
SUSE-SU-2024:1641-1
SUSE-SU-2024:1647-1
SUSE-SU-2024:1659-1
SUSE-SU-2024:1663-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse