CVE-2024-26955

medium

Description

In the Linux kernel, the following vulnerability has been resolved: nilfs2: prevent kernel bug at submit_bh_wbc() Fix a bug where nilfs_get_block() returns a successful status when searching and inserting the specified block both fail inconsistently. If this inconsistent behavior is not due to a previously fixed bug, then an unexpected race is occurring, so return a temporary error -EAGAIN instead. This prevents callers such as __block_write_begin_int() from requesting a read into a buffer that is not mapped, which would cause the BUG_ON check for the BH_Mapped flag in submit_bh_wbc() to fail.

References

https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html

https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html

https://git.kernel.org/stable/c/f0fe7ad5aff4f0fcf988913313c497de85f1e186

https://git.kernel.org/stable/c/ca581d237f3b8539c044205bb003de71d75d227c

https://git.kernel.org/stable/c/91e4c4595fae5e87069e44687ae879091783c183

https://git.kernel.org/stable/c/76ffbe911e2798c7296968f5fd72f7bf67207a8d

https://git.kernel.org/stable/c/48d443d200237782dc82e6b60663ec414ef02e39

https://git.kernel.org/stable/c/32eaee72e96590a75445c8a6c7c1057673b47e07

https://git.kernel.org/stable/c/269cdf353b5bdd15f1a079671b0f889113865f20

https://git.kernel.org/stable/c/192e9f9078c96be30b31c4b44d6294b24520fce5

https://git.kernel.org/stable/c/0c8aa4cfda4e4adb15d5b6536d155eca9c9cd44c

Details

Source: Mitre, NVD

Published: 2024-05-01

Updated: 2024-06-27

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium