CVE-2024-26869: f2fs: fix to truncate meta inode pages forcely
Published Apr 17, 2024
·Updated
f2fs: fix to truncate meta inode pages forcely
Affected Software
5 affected componentsFixes available
Linux Linux kernel>=4.19<6.6.23
Linux Linux kernel>=6.7<6.7.11
Linux Linux kernel>=6.8<6.8.2
debian/linux<=5.10.223-1, <=5.10.234-1, <=6.1.129-1, <=6.1.135-1
6.12.25-16.12.27-1
Microsoft cbl2 kernel 5.15.186.1-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Apr 17, 2024
CVE Published
via MITRE·10:27 AM
Data Sourced
via MITRE·10:27 AM
DescriptionSeverity
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 8, 2024
Data Sourced
via Launchpad·01:08 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·02:19 PM
RemedyDescriptionSeverityAffected Software
Sep 3, 2025
Data Sourced
via Microsoft·11:16 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·11:16 PM
Affected Software
Updated
via Microsoft·11:16 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-26869?
CVE-2024-26869 is classified as a moderate severity vulnerability in the Linux kernel.
2
How do I fix CVE-2024-26869?
To mitigate CVE-2024-26869, update your Linux kernel to version 6.12.11-1, 6.12.12-1, or a later version.
3
What systems are affected by CVE-2024-26869?
CVE-2024-26869 affects users running specific versions of the Linux kernel, including 5.10.223-1, 5.10.226-1, 6.1.119-1, and 6.1.123-1.
4
What type of vulnerability is CVE-2024-26869?
CVE-2024-26869 is a race condition vulnerability that can lead to data corruption in the f2fs filesystem.
5
Is CVE-2024-26869 commonly exploitable?
While CVE-2024-26869 can cause data corruption, its exploitation requires specific conditions within the Linux kernel's f2fs component.