CVE-2024-23850: Medium severity Linux Linux kernel vulnerability
In btrfsgetrootref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1 there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation.
Other sources
In btrfsgetrootref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23850?
CVE-2024-23850 has been classified as a critical vulnerability due to the potential for crashes in the Linux kernel.
How do I fix CVE-2024-23850?
To fix CVE-2024-23850, update your Linux kernel to version 6.7.1 or later.
What systems are affected by CVE-2024-23850?
CVE-2024-23850 affects the Linux kernel versions up to and including 6.7.1.
What causes the issue in CVE-2024-23850?
The issue in CVE-2024-23850 is caused by an assertion failure due to a subvolume being read too soon after its root item is inserted.
Is CVE-2024-23850 exploitable in production environments?
Yes, CVE-2024-23850 is exploitable in production environments, potentially leading to system crashes.