CVE-2024-26697

Updated: 2025-03-17 21:25:11.959185

Description:

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix data corruption in dsync block recovery for small block sizes The helper function nilfs_recovery_copy_block() of nilfs_recovery_dsync_blocks(), which recovers data from logs created by data sync writes during a mount after an unclean shutdown, incorrectly calculates the on-page offset when copying repair data to the file's page cache. In environments where the block size is smaller than the page size, this flaw can cause data corruption and leak uninitialized memory bytes during the recovery process. Fix these issues by correcting this byte offset calculation on the page.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-03-20 03:51:07
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-03-20 03:51:07
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-03-20 03:51:06
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-03-20 03:51:06
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-03-20 03:51:07
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-03-20 03:51:06
CloudLinux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-03-20 03:51:07
CloudLinux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-03-21 03:26:59
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-03-20 03:51:06
Oracle Linux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-03-21 03:26:59
Total: 14