Review reviewHigh

CVE-2024-49960

Linux Linux, debian linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: ext4: fix timer use-after-free on failed mount Syzbot has found an ODEBUG bug in ext4_fill_super The del_timer_sync function cancels the s_err_report timer, which reminds about filesystem errors daily. We should guarantee the timer is no longer active before kfree(sbi). When filesystem mounting fails, the flow goes to failed_mount3, where an error occurs when ext4_stop_mmpd is called, causing a read I/O failure. This triggers the ext4_handle_error function that ultimately re-arms the timer, leaving the s_err_report timer ac...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.10.22
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ext4: fix timer use-after-free on failed mount Syzbot has found an ODEBUG bug in ext4_fill_super The del_timer_sync function cancels the s_err_report timer, which reminds about filesystem errors daily. We should guarantee the timer is no longer active before kfree(sbi). When filesystem mounting fails, the flow goes to failed_mount3, where an error occurs when ext4_stop_mmpd is called, causing a read I/O failure. This triggers the ext4_handle_error function that ultimately re-arms the timer, leaving the s_err_report timer ac...

Affected product and versions

Product
Linux Linux, debian linux, linux kernel
Affected versions
>= 5e4f5138bd8522ebe231a137682d3857209a2c07 < 7aac0c17a8cdf4a3236991c1e60435c6a984076c, >= 618f003199c6188e01472b03cdbba227f1dc5f24 < 22e9b83f0f33bc5a7a3181769d1dccbf021f5b04, >= 618f003199c6188e01472b03cdbba227f1dc5f24 < cf3196e5e2f36cd80dab91ffae402e13935724bc, >= 618f003199c6188e01472b03cdbba227f1dc5f24 < 9203817ba46ebba7c865c8de2aba399537b6e891, >= 618f003199c6188e01472b03cdbba227f1dc5f24 < fa78fb51d396f4f2f80f8e96a3b1516f394258be, >= 618f003199c6188e01472b03cdbba227f1dc5f24 < b85569585d0154d4db1e4f9e3e6a4731d407feb0, >= 618f003199c6188e01472b03cdbba227f1dc5f24 < 0ce160c5bdb67081a62293028dc85758a8efb22a, >= cecfdb9cf9a700d1037066173abac0617f6788df, >= eb7b40d9d3785f7a131fb0b1f89bb6efa46c1833, >= 5.10.51 < 5.10.237, >= 5.12.18 < 5.13, >= 5.13.3 < 5.14, >= 5.14, 11.0, < 5.10.237, >= 5.11 < 5.15.181, >= 5.16 < 6.1.118, >= 6.2 < 6.6.55, >= 6.7 < 6.10.14, >= 6.11 < 6.11.3
Fixed versions
5.10.237, 5.15.181, 6.1.118, 6.6.55, 6.10.14, 6.11.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, debian linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2024-49960 — Linux Linux, debian linux, linux kernel | SECUFOCUS NOW