CVE-2024-49966

Updated: 2025-02-27 14:00:02.443363

Description:

In the Linux kernel, the following vulnerability has been resolved: ocfs2: cancel dqi_sync_work before freeing oinfo ocfs2_global_read_info() will initialize and schedule dqi_sync_work at the end, if error occurs after successfully reading global quota, it will trigger the following warning with CONFIG_DEBUG_OBJECTS_* enabled: ODEBUG: free active (active state 0) object: 00000000d8b0ce28 object type: timer_list hint: qsync_work_fn+0x0/0x16c This reports that there is an active delayed work when freeing oinfo in error handling, so cancel dqi_sync_work first. BTW, return status instead of -1 when .read_file_info fails.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:50
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2025-03-03 21:57:50
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:49
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:49
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:49
CentOS Stream 8 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:49
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2025-03-03 21:57:50
CloudLinux 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:47
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2025-03-03 21:57:49
Oracle Linux 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:49
Total: 14