CVE-2024-0775

Summary

A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while freeing the old quota file names before a potential failure, leading to a use-after-free.

Affected Software

VendorProductVersion RangeStatus
Linuxkernel0 < 4.14.315affected
Linuxkernel4.15 < 4.19.283affected
Linuxkernel4.20 < 5.4.243affected
Linuxkernel5.5 < 5.10.180affected
Linuxkernel5.11 < 5.15.112affected
Linuxkernel5.16 < 6.1.29affected
Linuxkernel6.2 < 6.2.16affected
Linuxkernel6.3 < 6.3.3affected

Weaknesses

  • CWE-416: Use After Free

Workarounds

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References