CVE-2024-44947

MEDIUM

Linux Kernel - Information Disclosure via Uninitialized Page Contents in FUSE Notify Store

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-44947. PoCs published by Abdurahmon3236.

AI-analyzed exploit summary This repository contains a functional PoC for CVE-2024-44947, demonstrating an information leak in the Linux kernel's FUSE module by triggering uninitialized memory exposure via mmap. The PoC includes advanced features like heuristic analysis and expanded memory dumps.

Description

In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page zeroing (because it can be used to change partial page contents). So fuse_notify_store() must be more careful to fully initialize page contents (including parts of the page that are beyond end-of-file) before marking the page uptodate. The current code can leave beyond-EOF page contents uninitialized, which makes these uninitialized page contents visible to userspace via mmap(). This is an information leak, but only affects systems which do not enable init-on-alloc (via CONFIG_INIT_ON_ALLOC_DEFAULT_ON=y or the corresponding kernel command line parameter).

Exploits (1)

nomisec WORKING POC
by Abdurahmon3236 · poc
https://github.com/Abdurahmon3236/CVE-2024-44947

This repository contains a functional PoC for CVE-2024-44947, demonstrating an information leak in the Linux kernel's FUSE module by triggering uninitialized memory exposure via mmap. The PoC includes advanced features like heuristic analysis and expanded memory dumps.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Linux kernel (FUSE module)
Auth required
Prerequisites: Access to /dev/fuse · Privileged user access
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 5.5
EPSS 0.0050
EPSS Percentile 66.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-665
Status published
Products (27)
linux/Kernel 2.6.36 - 4.19.321linux
linux/Kernel 4.20.0 - 5.4.283linux
linux/Kernel 5.11.0 - 5.15.166linux
linux/Kernel 5.16.0 - 6.1.107linux
linux/Kernel 5.5.0 - 5.10.225linux
linux/Kernel 6.2.0 - 6.6.48linux
linux/Kernel 6.7.0 - 6.10.7linux
Linux/Linux < 2.6.36
Linux/Linux 2.6.36
Linux/Linux 4.19.321 - 4.19.*
... and 17 more
Published Sep 02, 2024
Tracked Since Feb 18, 2026