CVE-2024-26792: btrfs: fix double free of anonymous device after snapshot creation failure
btrfs: fix double free of anonymous device after snapshot creation failure
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
Linux kernel (btrfs)to a version that resolves this vulnerability.Patch btrfs: fix double free of anonymous device after snapshot creation failure
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26792?
CVE-2024-26792 has a moderate severity rating due to the potential for memory corruption in the Linux kernel.
How do I fix CVE-2024-26792?
To fix CVE-2024-26792, update the Linux kernel to versions 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1, or any version from the remedy packages.
Which Linux kernel versions are affected by CVE-2024-26792?
The affected versions include Linux kernel versions from 5.10.210 to 5.11, and versions 5.15.149 to 5.16, among others.
What type of vulnerability is CVE-2024-26792?
CVE-2024-26792 is classified as a memory management vulnerability that involves a double free condition.
Can CVE-2024-26792 be exploited remotely?
CVE-2024-26792 is primarily a local vulnerability that may be exploited by users with local access to the system.