CVE-2024-26944: btrfs: zoned: fix use-after-free in do_zone_finish()
btrfs: zoned: fix use-after-free in dozonefinish()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
Linux kernel (btrfs)to a version that resolves this vulnerability.Patch btrfs: zoned: fix use-after-free in do_zone_finish()
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26944?
CVE-2024-26944 is classified as a high severity vulnerability due to the use-after-free flaw that could lead to potential system crashes or arbitrary code execution.
How do I fix CVE-2024-26944?
To remediate CVE-2024-26944, upgrade your Linux kernel to version 6.9-rc1 or any version above 6.12.11-1.
Which versions of the Linux kernel are affected by CVE-2024-26944?
CVE-2024-26944 affects Linux kernel versions up to 6.8.3 and specifically version 6.9-rc1.
What components are impacted by CVE-2024-26944?
CVE-2024-26944 impacts the btrfs file system related to device replacements, leading to a use-after-free condition.
Who reported the CVE-2024-26944 vulnerability?
The vulnerability CVE-2024-26944 was reported by a security researcher named Shinichiro.