CVE-2024-26601

MEDIUM

Linux Kernel - Buddy Bitmap Corruption via Fast Commit Replay

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed if under fc replay This mostly reverts commit 6bd97bf273bd ("ext4: remove redundant mb_regenerate_buddy()") and reintroduces mb_regenerate_buddy(). Based on code in mb_free_blocks(), fast commit replay can end up marking as free blocks that are already marked as such. This causes corruption of the buddy bitmap so we need to regenerate it in that case.

Scores

CVSS v3 5.5
EPSS 0.0028
EPSS Percentile 20.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (20)
linux/Kernel < 5.10.211linux
linux/Kernel 5.11.0 - 6.1.78linux
linux/Kernel 5.16.0 - 6.6.17linux
linux/Kernel 6.2.0 - 6.7.5linux
Linux/Linux < 5.11
Linux/Linux 0983142c5f17a62055ec851372273c3bc77e4788 - 94ebf71bddbcd4ab1ce43ae32c6cb66396d2d51a
Linux/Linux 5.10.181 - 5.10.211
Linux/Linux 5.10.211 - 5.10.*
Linux/Linux 5.11
Linux/Linux 5.15.150 - 5.15.*
... and 10 more
Published Feb 26, 2024
Tracked Since Feb 18, 2026