ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found()

Summary

CVECVE-2024-26773
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2024-04-03 17:15:53 UTC
Updated2026-08-04 11:17:03 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() Determine if the group block bitmap is corrupted before using ac_b_ex in ext4_mb_try_best_found() to avoid allocating blocks from a group with a corrupted block bitmap in the following concurrency and making the situation worse. ext4_mb_regular_allocator ext4_lock_group(sb, group) ext4_mb_good_group // check if the group bbitmap is corrupted ext4_mb_complex_scan_group // Scan group gets ac_b_ex but doesn't use it ext4_unlock_group(sb, group) ext4_mark_group_bitmap_corrupted(group) // The block bitmap was corrupted during // the group unlock gap. ext4_mb_try_best_found ext4_lock_group(ac->ac_sb, group) ext4_mb_use_best_found mb_mark_used // Allocating blocks in block bitmap corrupted group

Risk And Classification

Primary CVSS: v3.1 5.5 MEDIUM from [email protected]

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem Types: NVD-CWE-noinfo


VersionSourceTypeScoreSeverityVector
3.1[email protected]Primary5.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3.1CNADECLARED7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 163a203ddb36c36d4a1c942aececda0cc8d06aa7 21f8cfe79f776287459343e9cfa6055af61328ea git Not specified
CNA Linux Linux affected 163a203ddb36c36d4a1c942aececda0cc8d06aa7 260fc96283c0f594de18a1b045faf6d8fb42874d git Not specified
CNA Linux Linux affected 163a203ddb36c36d4a1c942aececda0cc8d06aa7 927794a02169778c9c2e7b25c768ab3ea8c1dc03 git Not specified
CNA Linux Linux affected 163a203ddb36c36d4a1c942aececda0cc8d06aa7 4c21fa60a6f4606f6214a38f50612b17b2f738f5 git Not specified
CNA Linux Linux affected 163a203ddb36c36d4a1c942aececda0cc8d06aa7 f97e75fa4e12b0aa0224e83fcbda8853ac2adf36 git Not specified
CNA Linux Linux affected 163a203ddb36c36d4a1c942aececda0cc8d06aa7 0184747b552d6b5a14db3b7fcc3b792ce64dedd1 git Not specified
CNA Linux Linux affected 163a203ddb36c36d4a1c942aececda0cc8d06aa7 a2576ae9a35c078e488f2c573e9e6821d651fbbe git Not specified
CNA Linux Linux affected 163a203ddb36c36d4a1c942aececda0cc8d06aa7 4530b3660d396a646aad91a787b6ab37cf604b53 git Not specified
CNA Linux Linux affected 3.12 Not specified
CNA Linux Linux unaffected 3.12 semver Not specified
CNA Linux Linux unaffected 4.19.308 4.19.* semver Not specified
CNA Linux Linux unaffected 5.4.270 5.4.* semver Not specified
CNA Linux Linux unaffected 5.10.211 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.150 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.80 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.19 6.6.* semver Not specified
CNA Linux Linux unaffected 6.7.7 6.7.* semver Not specified
CNA Linux Linux unaffected 6.8 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() - kernel/git/stable/linux.git - Linux kernel stable tree af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() - kernel/git/stable/linux.git - Linux kernel stable tree af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
lists.debian.org/debian-lts-announce/2024/06/msg00017.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org Mailing List
ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() - kernel/git/stable/linux.git - Linux kernel stable tree af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() - kernel/git/stable/linux.git - Linux kernel stable tree af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() - kernel/git/stable/linux.git - Linux kernel stable tree af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() - kernel/git/stable/linux.git - Linux kernel stable tree af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() - kernel/git/stable/linux.git - Linux kernel stable tree af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
lists.debian.org/debian-lts-announce/2024/06/msg00020.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org Mailing List
ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() - kernel/git/stable/linux.git - Linux kernel stable tree af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 6000567 Debian Security Update for linux (DSA 5658-1)

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report