CVE-2024-27033

MEDIUM

Linux Kernel 6.2-6.6.22, 6.7.0-6.7.10, 6.8.0-6.8.1 - Denial of Service via f2fs_bug_on() in verify_blkaddr()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to remove unnecessary f2fs_bug_on() to avoid panic verify_blkaddr() will trigger panic once we inject fault into f2fs_is_valid_blkaddr(), fix to remove this unnecessary f2fs_bug_on().

Scores

CVSS v3 5.5
EPSS 0.0027
EPSS Percentile 18.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (14)
linux/Kernel 6.2.0 - 6.6.23linux
linux/Kernel 6.7.0 - 6.7.11linux
linux/Kernel 6.8.0 - 6.8.2linux
Linux/Linux < 6.2
Linux/Linux 18792e64c86dd7e34ba28e4f61faba472b7bf5fc - 0386408036bfc8b50296d9e544ff91c4d52af2db
Linux/Linux 18792e64c86dd7e34ba28e4f61faba472b7bf5fc - 6633cdc8b2ebefcddcfcdacfd063105e60f39a49
Linux/Linux 18792e64c86dd7e34ba28e4f61faba472b7bf5fc - abe98a05e7162f64759bf9111108ebcb11322dec
Linux/Linux 18792e64c86dd7e34ba28e4f61faba472b7bf5fc - b896e302f79678451a94769ddd9e52e954c64fbb
Linux/Linux 6.2
Linux/Linux 6.6.23 - 6.6.*
... and 4 more
Published May 01, 2024
Tracked Since Feb 18, 2026