Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-46780— nilfs2: protect references to superblock parameters exposed in sysfs

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞。攻击者利用该漏洞可以获取敏感信息。

CVSS 7.8 · High EPSS 0.24% · P15

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux da7141fb78db915680616e15677539fc8140cf53< b90beafac05931cbfcb6b1bd4f67c1923f47040e affected
da7141fb78db915680616e15677539fc8140cf53< ba97ba173f9625d5f34a986088979eae8b80d38e affected
da7141fb78db915680616e15677539fc8140cf53< 157c0d94b4c40887329418c70ef4edd1a8d6b4ed affected
da7141fb78db915680616e15677539fc8140cf53< b14e7260bb691d7f563f61da07d61e3c8b59a614 affected
da7141fb78db915680616e15677539fc8140cf53< 19cfeba0e4b8eda51484fcf8cf7d150418e1d880 affected
da7141fb78db915680616e15677539fc8140cf53< 8c6e43b3d5f109cf9c61bc188fcc8175404e924f affected
da7141fb78db915680616e15677539fc8140cf53< 962562d4c70c5cdeb4e955d63ff2017c4eca1aad affected
da7141fb78db915680616e15677539fc8140cf53< 683408258917541bdb294cd717c210a04381931e affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-46780

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
nilfs2: protect references to superblock parameters exposed in sysfs
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nilfs2: protect references to superblock parameters exposed in sysfs The superblock buffers of nilfs2 can not only be overwritten at runtime for modifications/repairs, but they are also regularly swapped, replaced during resizing, and even abandoned when degrading to one side due to backing device issues. So, accessing them requires mutual exclusion using the reader/writer semaphore "nilfs->ns_sem". Some sysfs attribute show methods read this superblock buffer without the necessary mutual exclusion, which can cause problems with pointer dereferencing and memory access, so fix it.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞。攻击者利用该漏洞可以获取敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux da7141fb78db915680616e15677539fc8140cf53 ~ b90beafac05931cbfcb6b1bd4f67c1923f47040e -
Linux Linux 3.17 -

II. Public POCs for CVE-2024-46780

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-46780

登录查看更多情报信息。

Patches & Fixes for CVE-2024-46780 (2)

Same Patch Batch · Linux · 2024-09-18 · 85 CVEs total

CVE-2024-46717 9.8 CRITICAL net/mlx5e: SHAMPO, Fix incorrect page release
CVE-2024-46736 9.8 CRITICAL smb: client: fix double put of @cfile in smb2_rename_path()
CVE-2024-46796 9.8 CRITICAL smb: client: fix double put of @cfile in smb2_set_path_size()
CVE-2024-46755 8.8 HIGH wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()
CVE-2024-46750 7.8 HIGH PCI: Add missing bridge lock to pci_bus_lock()
CVE-2024-46800 7.8 HIGH sch/netem: fix use after free in netem_dequeue
CVE-2024-46716 7.8 HIGH dmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor
CVE-2024-46787 7.8 HIGH userfaultfd: fix checks for huge PMDs
CVE-2024-46734 7.8 HIGH btrfs: fix race between direct IO write and fsync when using same fd
CVE-2024-46738 7.8 HIGH VMCI: Fix use-after-free when removing resource in vmci_resource_remove()
CVE-2024-46740 7.8 HIGH binder: fix UAF caused by offsets overwrite
CVE-2024-46746 7.8 HIGH HID: amd_sfh: free driver_data after destroying hid device
CVE-2024-46781 7.8 HIGH nilfs2: fix missing cleanup on rollforward recovery error
CVE-2024-46741 7.8 HIGH misc: fastrpc: Fix double free of 'buf' in error path
CVE-2024-46751 7.8 HIGH btrfs: don't BUG_ON() when 0 reference count at btrfs_lookup_extent_info()
CVE-2024-46777 7.8 HIGH udf: Avoid excessive partition lengths
CVE-2024-46754 7.8 HIGH bpf: Remove tst_run from lwt_seg6local_prog_ops.
CVE-2024-46762 7.8 HIGH xen: privcmd: Fix possible access to a freed kirqfd instance
CVE-2024-46765 7.8 HIGH ice: protect XDP configuration with a mutex
CVE-2024-46771 7.8 HIGH can: bcm: Remove proc entry when dev is unregistered.

Showing top 20 of 85 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-46780

No comments yet


Leave a comment