CVE-2024-27035: f2fs: compress: fix to guarantee persisting compressed blocks by CP
Published May 1, 2024
·Updated
f2fs: compress: fix to guarantee persisting compressed blocks by CP
Affected Software
5 affected componentsFixes available
debian/linux<=5.10.223-1, <=5.10.234-1
6.1.129-16.1.135-16.12.25-16.12.27-1
Linux Linux kernel>=5.6<6.1.83
Linux Linux kernel>=6.2<6.6.23
Linux Linux kernel>=6.7<6.7.11
Linux Linux kernel>=6.8<6.8.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
May 1, 2024
CVE Published
via MITRE·12:53 PM
Data Sourced
via MITRE·12:53 PM
DescriptionSeverity
Data Sourced
via NVD·01:15 PM
Description
Data Sourced
via NVD·01:15 PM
RemedySeverityAffected Software
Jun 8, 2024
Data Sourced
via Launchpad·01:11 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·02:23 PM
RemedyDescriptionSeverityAffected Software
Sep 20, 2025
Data Sourced
via Microsoft·01:03 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-27035?
CVE-2024-27035 is classified as a moderate severity vulnerability in the Linux kernel that could lead to data corruption.
2
How do I fix CVE-2024-27035?
To fix CVE-2024-27035, upgrade to the recommended versions of the Linux package: 6.1.123-1, 6.1.119-1, or 6.12.10-1.
3
Which Linux versions are affected by CVE-2024-27035?
The affected Linux versions for CVE-2024-27035 include those up to and including 5.10.226-1.
4
What specific component of the Linux kernel does CVE-2024-27035 affect?
CVE-2024-27035 specifically affects the F2FS file system component related to block compression.
5
Is data loss possible due to CVE-2024-27035?
Yes, CVE-2024-27035 can lead to data corruption if data blocks are not persisted correctly during a checkpoint.