CVE-2024-47726

MEDIUM

Linux Kernel - Data Overwrite via Unfinished Direct IO in F2FS

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to wait dio completion It should wait all existing dio write IOs before block removal, otherwise, previous direct write IO may overwrite data in the block which may be reused by other inode.

Scores

CVSS v3 6.5
EPSS 0.0082
EPSS Percentile 53.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (20)
linux/Kernel 3.8.0 - 5.10.235linux
linux/Kernel 5.11.0 - 5.15.179linux
linux/Kernel 5.16.0 - 6.1.129linux
linux/Kernel 6.2.0 - 6.6.70linux
linux/Kernel 6.7.0 - 6.11.2linux
Linux/Linux < 3.8
Linux/Linux 3.8
Linux/Linux 5.10.235 - 5.10.*
Linux/Linux 5.15.179 - 5.15.*
Linux/Linux 6.1.129 - 6.1.*
... and 10 more
Published Oct 21, 2024
Tracked Since Feb 18, 2026