CVE-2024-27034

MEDIUM

Linux Kernel 5.6-6.8.1 Data Corruption via Compressed Cluster Overwrite

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to cover normal cluster write with cp_rwsem When we overwrite compressed cluster w/ normal cluster, we should not unlock cp_rwsem during f2fs_write_raw_pages(), otherwise data will be corrupted if partial blocks were persisted before CP & SPOR, due to cluster metadata wasn't updated atomically.

Scores

CVSS v3 5.5
EPSS 0.0027
EPSS Percentile 19.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (20)
linux/Kernel 5.16.0 - 6.1.83linux
linux/Kernel 5.6.0 - 5.15.153linux
linux/Kernel 6.2.0 - 6.6.23linux
linux/Kernel 6.7.0 - 6.7.11linux
linux/Kernel 6.8.0 - 6.8.2linux
Linux/Linux < 5.6
Linux/Linux 4c8ff7095bef64fc47e996a938f7d57f9e077da3 - 2b1b14d9fc94b8feae20808684c8af28ec80f45b
Linux/Linux 4c8ff7095bef64fc47e996a938f7d57f9e077da3 - 52982edfcefd475cc34af663d5c47c0cddaa5739
Linux/Linux 4c8ff7095bef64fc47e996a938f7d57f9e077da3 - 542c8b3c774a480bfd0804291a12f6f2391b0cd1
Linux/Linux 4c8ff7095bef64fc47e996a938f7d57f9e077da3 - 75abfd61392b1db391bde6d738a30d685b843286
... and 10 more
Published May 01, 2024
Tracked Since Feb 18, 2026