CVE-2024-37354: btrfs: fix crash on racing fsync and size-extending write into prealloc
Published Jun 25, 2024
·Updated
btrfs: fix crash on racing fsync and size-extending write into prealloc
Affected Software
7 affected componentsFixes available
debian/linux<=5.10.223-1, <=5.10.234-1
6.1.129-16.1.135-16.12.25-16.12.27-1
Linux Linux kernel<6.1.94
Linux Linux kernel>=6.2<6.6.34
Linux Linux kernel>=6.7<6.9.5
Linux Linux kernel=6.10-rc1
Linux Linux kernel=6.10-rc2
Microsoft cbl2 kernel 5.15.186.1-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Jun 25, 2024
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionSeverity
Data Sourced
via NVD·03:15 PM
Description
Data Sourced
via NVD·03:15 PM
RemedySeverityWeaknessAffected Software
Apr 27, 2025
Data Sourced
via Ubuntu·05:12 PM
RemedyDescriptionSeverityAffected Software
Sep 20, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·01:01 AM
Affected Software
Updated
via Microsoft·01:01 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-37354?
CVE-2024-37354 is considered to have a high severity due to the potential for system crashes in the Linux kernel.
2
How do I fix CVE-2024-37354?
To fix CVE-2024-37354, upgrade to the patched versions of the Linux kernel, specifically 6.1.123-1, 6.1.119-1, or 6.12.11-1.
3
What versions of the Linux kernel are affected by CVE-2024-37354?
CVE-2024-37354 affects Linux kernel versions up to 5.10.226-1.
4
What is the nature of the vulnerability in CVE-2024-37354?
CVE-2024-37354 involves a crash caused by a race condition during fsync operations and size-extending writes in btrfs.
5
Where can I find more information about CVE-2024-37354?
For more information on CVE-2024-37354, refer to the official Linux kernel development logs.