#VU93770 Improper locking in Linux kernel


Published: 2024-07-04

Vulnerability identifier: #VU93770

Vulnerability risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-26601

CWE-ID: CWE-667

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the ext4_mb_generate_buddy() and mb_free_blocks() functions in fs/ext4/mballoc.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/78327acd4cdc4a1601af718b781eece577b6b7d4
http://git.kernel.org/stable/c/ea42d6cffb0dd27a417f410b9d0011e9859328cb
http://git.kernel.org/stable/c/6b0d48647935e4b8c7b75d1eccb9043fcd4ee581
http://git.kernel.org/stable/c/c9b528c35795b711331ed36dc3dbee90d5812d4e
http://git.kernel.org/stable/c/94ebf71bddbcd4ab1ce43ae32c6cb66396d2d51a
http://git.kernel.org/stable/c/c1317822e2de80e78f137d3a2d99febab1b80326
http://lists.debian.org/debian-lts-announce/2024/06/msg00017.html


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability