#VU98941 NULL pointer dereference in Linux kernel - CVE-2024-49957


Vulnerability identifier: #VU98941

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-49957

CWE-ID: CWE-476

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the ocfs2_journal_shutdown() function in fs/ocfs2/journal.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/bf605ae98dab5c15c5b631d4d7f88898cb41b649
https://git.kernel.org/stable/c/ff55291fb36779819211b596da703389135f5b05
https://git.kernel.org/stable/c/82dfdd1e31e774578f76ce6dc90c834f96403a0f
https://git.kernel.org/stable/c/86a89e75e9e4dfa768b97db466ad6bedf2e7ea5b
https://git.kernel.org/stable/c/f60e94a83db799bde625ac8671a5b4a6354e7120
https://git.kernel.org/stable/c/387bf565cc03e2e8c720b8b4798efea4aacb6962
https://git.kernel.org/stable/c/5784d9fcfd43bd853654bb80c87ef293b9e8e80a


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability