CVE-2024-0775

A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while freeing the old quota file names before a potential failure, leading to a use-after-free.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.4:rc1:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

29 Jan 2024, 19:08

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla de use-after-free en __ext4_remount en fs/ext4/super.c en ext4 en el kernel de Linux. Esta falla permite que un usuario local cause un problema de fuga de información mientras libera los nombres de archivos de cuota antiguos antes de una posible falla, lo que lleva a un use-after-free.
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.4:rc1:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 6.7
v2 : unknown
v3 : 7.1
References () https://access.redhat.com/security/cve/CVE-2024-0775 - () https://access.redhat.com/security/cve/CVE-2024-0775 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2259414 - () https://bugzilla.redhat.com/show_bug.cgi?id=2259414 - Issue Tracking, Third Party Advisory
References () https://scm.linefinity.com/common/linux-stable/commit/4c0b4818b1f636bc96359f7817a2d8bab6370162 - () https://scm.linefinity.com/common/linux-stable/commit/4c0b4818b1f636bc96359f7817a2d8bab6370162 - Patch
First Time Redhat enterprise Linux
Linux linux Kernel
Linux
Redhat

22 Jan 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-22 13:15

Updated : 2024-01-29 19:08


NVD link : CVE-2024-0775

Mitre link : CVE-2024-0775

CVE.ORG link : CVE-2024-0775


JSON object : View

Products Affected

linux

  • linux_kernel

redhat

  • enterprise_linux
CWE
CWE-416

Use After Free