Kernel: use-after-free while changing the mount option in __ext4_remount leading
CVE-2024-0775
7.1HIGH
What is CVE-2024-0775?
A use-after-free vulnerability exists in the ext4 file system within the Linux kernel. This flaw occurs due to improper handling of old quota file names, which can lead to inactive memory being accessed during a failure condition. A local user could exploit this issue to potentially leak sensitive information or impact system stability through unintended access to freed memory regions. The vulnerability resides specifically in the __ext4_remount function located in fs/ext4/super.c, making it crucial for system administrators to monitor and patch affected systems promptly to mitigate risks.
Affected Version(s)
Kernel 6.4-rc2