CVE-2024-42077

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jul 29, 2024
Updated: Jul 30, 2024

Summary

CVE-2024-42077 is a vulnerability affecting the Linux kernel's ocfs2 file system. The issue lies in the estimation of transaction credits for IO operations, which can lead to insufficient credits and an OCFS2 abort. The vulnerability occurs when the IO contains many single block extents, causing the transaction to fail to extend and eventually exhaust all transaction credits. To mitigate this issue, the code has been updated to ensure the transaction always has enough credits before marking an extent written. This vulnerability was discovered in a heavily fragmented OCFS2 filesystem, causing a kernel panic and system crash.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share