🛡️ AZL-50754 — kernel

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

CVE-2024-47736 affecting package kernel 5.15.200.1-1

In the Linux kernel, the following vulnerability has been resolved:

erofs: handle overlapped pclusters out of crafted images properly

syzbot reported a task hang issue due to a deadlock case where it is

waiting for the folio lock of a cached folio that will be used for

cache I/Os.

After looking into the crafted fuzzed image, I found it's formed with

several overlapped big pclusters as below:

Ext: logical offset | length : physical offset | length

0: 0.. 16384 | 16384 : 151552.. 167936 | 16384

1: 16384.. 32768 | 16384 : 155648.. 172032 | 16384

2: 32768.. 49152 | 16384 : 537223168.. 537239552 | 16384

...

Here, extent 0/1 are physically overlapped although it's entirely

_impossible_ for normal filesystem images generated by mkfs.

First, managed folios containing compressed data will be marked as

up-to-date and then unlocked immediately (unlike in-place folios) when

compressed I/Os are complete. If physical blocks are not submitted in

the incremental order, there should be separate BIOs to avoid dependency

issues. However, the current code mis-arranges z_erofs_fill_bio_vec()

and BIO submission which causes unexpected BIO waits.

Second, managed folios will be connected to their own pclusters for

efficient inter-queries. However, this is somewhat hard to implement

easily if overlapped big pclusters exist. Again, these only appear in

fuzzed images so let's simply fall back to temporary short-lived pages

for correctness.

Additionally, it justifies that referenced managed folios cannot be

truncated for now and reverts part of commit 2080ca1ed3e4 ("erofs: tidy

up struct z_erofs_bvec") for simplicity although it shouldn't be any

difference.

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Affected software

AZL-50754 is recorded against 1 package.

  • kernel

Timeline and source

Published on 21 October 2024 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

nvd.nist.gov (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-10-21
Updated 2026-08-12
Modified 2026-04-21
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel

Similar Threats

Free Vulnerability Check

Is your site affected by AZL-50754?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-50754 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.