跳转到帖子

Amazon Linux AMI 2: CVE-2024-49960: Security patch for kernel-livepatch-5.10.227-219.884, kernel-livepatch-5.10.228-219.884, kernel-livepatch-5.10.230-223.885, kernel-livepatch-5.10.233-223.887 (Multiple Advisories)

recommended_posts

发布于
  • Members

Amazon Linux AMI 2: CVE-2024-49960: Security patch for kernel-livepatch-5.10.227-219.884, kernel-livepatch-5.10.228-219.884, kernel-livepatch-5.10.230-223.885, kernel-livepatch-5.10.233-223.887 (Multiple Advisories)

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
10/21/2024
Created
02/05/2025
Added
02/04/2025
Modified
02/04/2025

Description

In the Linux kernel, the following vulnerability has been resolved: ext4: fix timer use-after-free on failed mount Syzbot has found an ODEBUG bug in ext4_fill_super The del_timer_sync function cancels the s_err_report timer, which reminds about filesystem errors daily. We should guarantee the timer is no longer active before kfree(sbi). When filesystem mounting fails, the flow goes to failed_mount3, where an error occurs when ext4_stop_mmpd is called, causing a read I/O failure. This triggers the ext4_handle_error function that ultimately re-arms the timer, leaving the s_err_report timer active before kfree(sbi) is called. Fix the issue by canceling the s_err_report timer after calling ext4_stop_mmpd.

Solution(s)

  • amazon-linux-ami-2-upgrade-kernel-livepatch-5-10-227-219-884
  • amazon-linux-ami-2-upgrade-kernel-livepatch-5-10-228-219-884
  • amazon-linux-ami-2-upgrade-kernel-livepatch-5-10-230-223-885
  • amazon-linux-ami-2-upgrade-kernel-livepatch-5-10-233-223-887

References

  • https://attackerkb.com/topics/cve-2024-49960
  • AL2/ALASLIVEPATCH-2025-195
  • AL2/ALASLIVEPATCH-2025-196
  • AL2/ALASLIVEPATCH-2025-197
  • AL2/ALASLIVEPATCH-2025-198
  • CVE - 2024-49960
  • 查看数 696
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…