Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-26696— nilfs2: fix hang in nilfs_lookup_dirty_data_buffers()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于存在挂起问题。

AI Predicted 5.5 Difficulty: Easy EPSS 0.19% · P8

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 1d1d1a767206fbe5d4c69493b7e6d2a8d08cc0a0< 228742b2ddfb99dfd71e5a307e6088ab6836272e affected
1d1d1a767206fbe5d4c69493b7e6d2a8d08cc0a0< 862ee4422c38be5c249844a684b00d0dbe9d1e46 affected
1d1d1a767206fbe5d4c69493b7e6d2a8d08cc0a0< 98a4026b22ff440c7f47056481bcbbe442f607d6 affected
1d1d1a767206fbe5d4c69493b7e6d2a8d08cc0a0< 7e9b622bd0748cc104d66535b76d9b3535f9dc0f affected
1d1d1a767206fbe5d4c69493b7e6d2a8d08cc0a0< 8494ba2c9ea00a54d5b50e69b22c55a8958bce32 affected
1d1d1a767206fbe5d4c69493b7e6d2a8d08cc0a0< ea5ddbc11613b55e5128c85f57b08f907abd9b28 affected
1d1d1a767206fbe5d4c69493b7e6d2a8d08cc0a0< e38585401d464578d30f5868ff4ca54475c34f7d affected
1d1d1a767206fbe5d4c69493b7e6d2a8d08cc0a0< 38296afe3c6ee07319e01bb249aa4bb47c07b534 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-26696

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
nilfs2: fix hang in nilfs_lookup_dirty_data_buffers()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix hang in nilfs_lookup_dirty_data_buffers() Syzbot reported a hang issue in migrate_pages_batch() called by mbind() and nilfs_lookup_dirty_data_buffers() called in the log writer of nilfs2. While migrate_pages_batch() locks a folio and waits for the writeback to complete, the log writer thread that should bring the writeback to completion picks up the folio being written back in nilfs_lookup_dirty_data_buffers() that it calls for subsequent log creation and was trying to lock the folio. Thus causing a deadlock. In the first place, it is unexpected that folios/pages in the middle of writeback will be updated and become dirty. Nilfs2 adds a checksum to verify the validity of the log being written and uses it for recovery at mount, so data changes during writeback are suppressed. Since this is broken, an unclean shutdown could potentially cause recovery to fail. Investigation revealed that the root cause is that the wait for writeback completion in nilfs_page_mkwrite() is conditional, and if the backing device does not require stable writes, data may be modified without waiting. Fix these issues by making nilfs_page_mkwrite() wait for writeback to finish regardless of the stable write requirement of the backing device.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于存在挂起问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 1d1d1a767206fbe5d4c69493b7e6d2a8d08cc0a0 ~ 228742b2ddfb99dfd71e5a307e6088ab6836272e -
Linux Linux 3.9 -

II. Public POCs for CVE-2024-26696

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-26696

请登录查看更多情报信息。

Mailing List Discussions for CVE-2024-26696 (2)

Other References for CVE-2024-26696 (8)

Same Patch Batch · Linux · 2024-04-03 · 94 CVEs total

CVE-2024-26760 9.8 CRITICAL scsi: target: pscsi: Fix bio_put() for error case
CVE-2024-26779 8.8 HIGH wifi: mac80211: fix race condition on enabling fast-xmit
CVE-2024-26689 8.8 HIGH ceph: prevent use-after-free in encode_cap_msg()
CVE-2024-26692 8.3 HIGH smb: Fix regression in writes when non-standard maximum write size negotiated
CVE-2024-26736 8.1 HIGH afs: Increase buffer size in afs_update_volume_status()
CVE-2024-26704 7.8 HIGH ext4: fix double-free of blocks due to wrong extents moved_len
CVE-2024-26728 7.8 HIGH drm/amd/display: fix null-pointer dereference on edid reading
CVE-2023-52637 7.8 HIGH can: j1939: Fix UAF in j1939_sk_match_filter during setsockopt(SO_J1939_FILTER)
CVE-2024-26718 7.8 HIGH dm-crypt, dm-verity: disable tasklets
CVE-2024-26706 7.8 HIGH parisc: Fix random data corruption from exception handler
CVE-2024-26712 7.8 HIGH powerpc/kasan: Fix addr error caused by page alignment
CVE-2024-26699 7.8 HIGH drm/amd/display: Fix array-index-out-of-bounds in dcn35_clkmgr
CVE-2024-26737 7.8 HIGH bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel
CVE-2024-26697 7.8 HIGH nilfs2: fix data corruption in dsync block recovery for small block sizes
CVE-2024-26748 7.8 HIGH usb: cdns3: fix memory double free when handle zero packet
CVE-2024-26773 7.8 HIGH ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found()
CVE-2024-26772 7.8 HIGH ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal()
CVE-2024-26766 7.8 HIGH IB/hfi1: Fix sdma.h tx->num_descs off-by-one error
CVE-2024-26739 7.8 HIGH net/sched: act_mirred: don't override retval if we already lost the skb
CVE-2024-26759 7.8 HIGH mm/swap: fix race when skipping swapcache

Showing top 20 of 94 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-26696

No comments yet


Leave a comment