CVE-2024-49966

Updated: 2025-08-20 02:14:45.700826

Description:

In the Linux kernel, the following vulnerability has been resolved: ocfs2: cancel dqi_sync_work before freeing oinfo ocfs2_global_read_info() will initialize and schedule dqi_sync_work at the end, if error occurs after successfully reading global quota, it will trigger the following warning with CONFIG_DEBUG_OBJECTS_* enabled: ODEBUG: free active (active state 0) object: 00000000d8b0ce28 object type: timer_list hint: qsync_work_fn+0x0/0x16c This reports that there is an active delayed work when freeing oinfo in error handling, so cancel dqi_sync_work first. BTW, return status instead of -1 when .read_file_info fails.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:50
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2025-03-03 21:57:50
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:49
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:49
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:49
CentOS Stream 8 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:49
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2025-03-03 21:57:50
CloudLinux 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:47
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2025-03-03 21:57:49
Oracle Linux 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-03-03 21:57:49
Total: 14