Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-26601— ext4: regenerate buddy after block freeing failed if under fc replay

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux Kernel 存在安全漏洞,该漏洞源于 ext4 存在安全漏洞。

CVSS 7.8 · High EPSS 0.29% · P20

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 15

VendorProduct Version RangeStatus
Linux Linux 0983142c5f17a62055ec851372273c3bc77e4788< 94ebf71bddbcd4ab1ce43ae32c6cb66396d2d51a affected
6bd97bf273bdb4944904e57480f6545bca48ad77< c1317822e2de80e78f137d3a2d99febab1b80326 affected
6bd97bf273bdb4944904e57480f6545bca48ad77< 78327acd4cdc4a1601af718b781eece577b6b7d4 affected
6bd97bf273bdb4944904e57480f6545bca48ad77< ea42d6cffb0dd27a417f410b9d0011e9859328cb affected
6bd97bf273bdb4944904e57480f6545bca48ad77< 6b0d48647935e4b8c7b75d1eccb9043fcd4ee581 affected
6bd97bf273bdb4944904e57480f6545bca48ad77< c9b528c35795b711331ed36dc3dbee90d5812d4e affected
5.10.181< 5.10.211 affected
5.11 affected
… +7 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-26601

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ext4: regenerate buddy after block freeing failed if under fc replay
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed if under fc replay This mostly reverts commit 6bd97bf273bd ("ext4: remove redundant mb_regenerate_buddy()") and reintroduces mb_regenerate_buddy(). Based on code in mb_free_blocks(), fast commit replay can end up marking as free blocks that are already marked as such. This causes corruption of the buddy bitmap so we need to regenerate it in that case.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux Kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux Kernel 存在安全漏洞,该漏洞源于 ext4 存在安全漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 0983142c5f17a62055ec851372273c3bc77e4788 ~ 94ebf71bddbcd4ab1ce43ae32c6cb66396d2d51a -
Linux Linux 5.11 -

II. Public POCs for CVE-2024-26601

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-26601

请登录查看更多情报信息。

Mailing List Discussions for CVE-2024-26601 (1)

Other References for CVE-2024-26601 (6)

Same Patch Batch · Linux · 2024-02-24 · 6 CVEs total

CVE-2024-26605 PCI/ASPM: Fix deadlock when enabling ASPM
CVE-2024-26603 x86/fpu: Stop relying on userspace for info to fault in xsave buffer
CVE-2024-26604 Revert "kobject: Remove redundant checks for whether ktype is NULL"
CVE-2024-26602 sched/membarrier: reduce the ability to hammer on sys_membarrier
CVE-2024-26600 phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP

IV. Related Vulnerabilities

V. Comments for CVE-2024-26601

No comments yet


Leave a comment