Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-42295— nilfs2: handle inconsistent state in nilfs_btnode_create_block()

EPSS 0.01% · P2

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinuxa60be987d45dd510aeb54389526f9957cfab106c< 19cce46238ffe3546e44b9c74057103ff8b24c62affected
a60be987d45dd510aeb54389526f9957cfab106c< 02b87e6334a38c65eef49848d3f1ac422f0b2a44affected
a60be987d45dd510aeb54389526f9957cfab106c< 5f0a6800b8aec1b453c7fe4c44fcaac5ffe9d52eaffected
a60be987d45dd510aeb54389526f9957cfab106c< e34191cce3ee63dfa5fb241904aaf2a042d5b6d8affected
a60be987d45dd510aeb54389526f9957cfab106c< 012be828a118bf496e666ef1fc47fc0e7358ada2affected
a60be987d45dd510aeb54389526f9957cfab106c< be56dfc9be0604291267c07b0e27a69a6bda4899affected
a60be987d45dd510aeb54389526f9957cfab106c< 366c3f688dd0288cbe38af1d3a886b5c62372e4aaffected
a60be987d45dd510aeb54389526f9957cfab106c< 4811f7af6090e8f5a398fbdd766f903ef6c0d787affected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-42295

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
nilfs2: handle inconsistent state in nilfs_btnode_create_block()
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nilfs2: handle inconsistent state in nilfs_btnode_create_block() Syzbot reported that a buffer state inconsistency was detected in nilfs_btnode_create_block(), triggering a kernel bug. It is not appropriate to treat this inconsistency as a bug; it can occur if the argument block address (the buffer index of the newly created block) is a virtual block number and has been reallocated due to corruption of the bitmap used to manage its allocation state. So, modify nilfs_btnode_create_block() and its callers to treat it as a possible filesystem error, rather than triggering a kernel bug.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于nilfs2在nilfs_btnode_create_block函数中存在状态不一致问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux a60be987d45dd510aeb54389526f9957cfab106c ~ 19cce46238ffe3546e44b9c74057103ff8b24c62 -
LinuxLinux 2.6.30 -

II. Public POCs for CVE-2024-42295

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-42295

登录查看更多情报信息。
Patch · 1

Same Patch Batch · Linux · 2024-08-17 · 109 CVEs total

CVE-2024-43820dm-raid: Fix WARN_ON_ONCE check for sync_thread in raid_resume
CVE-2024-43833media: v4l: async: Fix NULL pointer dereference in adding ancillary links
CVE-2024-43831media: mediatek: vcodec: Handle invalid decoder vsi
CVE-2024-43832s390/uv: Don't call folio_wait_writeback() without a folio reference
CVE-2024-43830leds: trigger: Unregister sysfs attributes before calling deactivate()
CVE-2024-43829drm/qxl: Add check for drm_cvt_mode
CVE-2024-43828ext4: fix infinite loop when replaying fast_commit
CVE-2024-43827drm/amd/display: Add null check before access structs
CVE-2024-43826nfs: pass explicit offset/count to trace events
CVE-2024-43825iio: Fix the sorting functionality in iio_gts_build_avail_time_table
CVE-2024-43823PCI: keystone: Fix NULL pointer dereference in case of DT error in ks_pcie_setup_rc_app_re
CVE-2024-43824PCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init()
CVE-2024-43822ASoc: PCM6240: Return directly after a failed devm_kzalloc() in pcmdevice_i2c_probe()
CVE-2024-43821scsi: lpfc: Fix a possible null pointer dereference
CVE-2024-42318landlock: Don't lose track of restrictions on cred_transfer
CVE-2024-42321net: flow_dissector: use DEBUG_NET_WARN_ON_ONCE
CVE-2024-42320s390/dasd: fix error checks in dasd_copy_pair_store()
CVE-2024-42319mailbox: mtk-cmdq: Move devm_mbox_controller_register() after devm_pm_runtime_enable()
CVE-2024-42322ipvs: properly dereference pe in ip_vs_add_service
CVE-2024-42317mm/huge_memory: avoid PMD-size page cache if needed

Showing top 20 of 109 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-42295

No comments yet


Leave a comment