Use-After-Free Vulnerability in Linux Kernel Btrfs File System
CVE-2024-57896

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
15 January 2025

What is CVE-2024-57896?

A vulnerability in the Btrfs file system of the Linux kernel can lead to a use-after-free condition. During the unmount process, the cleaner thread is stopped, freeing its associated task structure. However, a worker from the delalloc_workers queue may still execute operations that reference the now-freed cleaner thread, leading to potential memory corruption. This can result in crashes or unexpected behaviors in systems using affected versions of the Linux kernel. Ensuring timely updates and applying patches is critical to safeguarding systems against this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux fd340d0f68cc87badfc9efcb226f23a5428826a0

Linux fd340d0f68cc87badfc9efcb226f23a5428826a0 < 63f4b594a688bf922e8691f0784679aa7af7988c

Linux fd340d0f68cc87badfc9efcb226f23a5428826a0 < 1ea629e7bb2fb40555e5e01a1b5095df31287017

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.