CVE-2024-46840
MEDIUMLinux Kernel - Denial of Service via Btrfs Snapshot Deletion
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: btrfs: clean up our handling of refs == 0 in snapshot delete In reada we BUG_ON(refs == 0), which could be unkind since we aren't holding a lock on the extent leaf and thus could get a transient incorrect answer. In walk_down_proc we also BUG_ON(refs == 0), which could happen if we have extent tree corruption. Change that to return -EUCLEAN. In do_walk_down() we catch this case and handle it correctly, however we return -EIO, which -EUCLEAN is a more appropriate error code. Finally in walk_up_proc we have the same BUG_ON(refs == 0), so convert that to proper error handling. Also adjust the error message so we can actually do something with the information.
References (10)
Core 10
Core References
Scores
CVSS v3
5.5
EPSS
0.0026
EPSS Percentile
17.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (26)
linux/Kernel
2.6.31 - 4.19.322linux
linux/Kernel
4.20.0 - 5.4.284linux
linux/Kernel
5.11.0 - 5.15.167linux
linux/Kernel
5.16.0 - 6.1.110linux
linux/Kernel
5.5.0 - 5.10.226linux
linux/Kernel
6.2.0 - 6.6.51linux
linux/Kernel
6.7.0 - 6.10.10linux
Linux/Linux
< 2.6.31
Linux/Linux
2.6.31
Linux/Linux
2c47e605a91dde6b0514f689645e7ab336c8592a - 03804641ec2d0da4fa088ad21c88e703d151ce16
... and 16 more
Published
Sep 27, 2024
Tracked Since
Feb 18, 2026