PT-2024-8237 · Linux+8 · Linux Kernel+8
Baokun Li
·
Published
2024-09-03
·
Updated
2025-09-29
·
CVE-2024-49884
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.58
Description:
The issue is related to a slab-use-after-free vulnerability in the
ext4 split extent at() function of the Linux kernel's ext4 file system. This vulnerability can be triggered when the ext4 split extent at() function is called, leading to a use-after-free error. The vulnerability may allow an attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is caused by the reuse of previously freed memory.Recommendations:
To resolve the issue, update the Linux kernel to version 6.6.58 or later. As a temporary workaround, consider restricting access to the vulnerable
ext4 split extent at() function until a patch is available. Avoid using the ext4 ext show leaf() function with the path variable as input until the issue is resolved.Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu