Bug 2273119 (CVE-2024-26697)
Summary: | CVE-2024-26697 kernel: nilfs2: fix data corruption in dsync block recovery for small block sizes | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Robb Gatica <rgatica> |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | acaringi, allarkin, aquini, bhu, chwhite, cye, cyin, dbohanno, debarbos, dfreiber, drow, dvlasenk, esandeen, ezulian, hkrzesin, jarod, jburrell, jdenham, jfaracco, jlelli, joe.lawrence, jshortt, jstancek, jwyatt, kcarcia, ldoskova, lgoncalv, lzampier, mleitner, mmilgram, mstowell, nmurray, ptalbert, rparrazo, rrobaina, rvrbovsk, rysulliv, scweaver, sidakwo, sukulkar, tglozar, tyberry, vkumar, wcosta, williams, wmealing, ycote, ykopkova, zhijwang |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | kernel 4.19.307, kernel 5.4.269, kernel 5.10.210, kernel 5.15.149, kernel 6.1.79, kernel 6.6.18, kernel 6.7.6, kernel 6.8 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in the Linux kernel, which affects the NILFS2 file system. This issue involves data corruption during dsync block recovery operations when using small block sizes, possibly leading to unexpected data loss or corruption.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2024-04-22 11:09:27 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2273120 | ||
Bug Blocks: | 2273079 |
Description
Robb Gatica
2024-04-03 22:47:38 UTC
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2273120] For future reference, we don't ship nilfs2 in RHEL. No nilfs2 issues will ever affect rhel8 or rhel9. Linked issues have been closed NOTABUG. The result of automatic check (that is developed by Alexander Larkin) for this CVE-2024-26697 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built). |