Review reviewHigh

CVE-2024-49966

Linux Linux, debian linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: ocfs2: cancel dqi_sync_work before freeing oinfo ocfs2_global_read_info() will initialize and schedule dqi_sync_work at the end, if error occurs after successfully reading global quota, it will trigger the following warning with CONFIG_DEBUG_OBJECTS_* enabled: ODEBUG: free active (active state 0) object: 00000000d8b0ce28 object type: timer_list hint: qsync_work_fn+0x0/0x16c This reports that there is an active delayed work when freeing oinfo in error handling, so cancel dqi_sync_work first. BTW, return status instead of -1...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.10.22
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ocfs2: cancel dqi_sync_work before freeing oinfo ocfs2_global_read_info() will initialize and schedule dqi_sync_work at the end, if error occurs after successfully reading global quota, it will trigger the following warning with CONFIG_DEBUG_OBJECTS_* enabled: ODEBUG: free active (active state 0) object: 00000000d8b0ce28 object type: timer_list hint: qsync_work_fn+0x0/0x16c This reports that there is an active delayed work when freeing oinfo in error handling, so cancel dqi_sync_work first. BTW, return status instead of -1...

Affected product and versions

Product
Linux Linux, debian linux, linux kernel
Affected versions
>= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < fc5cc716dfbdc5fd5f373ff3b51358174cf88bfc, >= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < 89043e7ed63c7fc141e68ea5a79758ed24b6c699, >= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < 14114d8148db07e7946fb06b56a50cfa425e26c7, >= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < 4173d1277c00baeedaaca76783e98b8fd0e3c08d, >= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < bbf41277df8b33fbedf4750a9300c147e8f104eb, >= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < ef768020366f47d23f39c4f57bcb03af6d1e24b3, >= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < a4346c04d055bf7e184c18a73dbd23b6a9811118, >= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < 0d707a33c84b371cb66120e198eed3374726ddd8, >= 171bf93ce11f4c9929fdce6ce63df8da2f3c4475 < 35fccce29feb3706f649726d410122dd81b92c18, >= 2.6.29, 11.0, >= 2.6.29 < 4.19.323, >= 4.20 < 5.4.285, >= 5.5 < 5.10.227, >= 5.11 < 5.15.168, >= 5.16 < 6.1.113, >= 6.2 < 6.6.55, >= 6.7 < 6.10.14, >= 6.11 < 6.11.3
Fixed versions
4.19.323, 5.4.285, 5.10.227, 5.15.168, 6.1.113, 6.6.55, 6.10.14, 6.11.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, debian linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2024-49966 — Linux Linux, debian linux, linux kernel | SECUFOCUS NOW