🛡️ AZL-50788 — kernel

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

CVE-2024-47690 affecting package kernel for versions less than 5.15.173.1-1

In the Linux kernel, the following vulnerability has been resolved:

f2fs: get rid of online repaire on corrupted directory

syzbot reports a f2fs bug as below:

kernel BUG at fs/f2fs/inode.c:896!

RIP: 0010:f2fs_evict_inode+0x1598/0x15c0 fs/f2fs/inode.c:896

Call Trace:

evict+0x532/0x950 fs/inode.c:704

dispose_list fs/inode.c:747 [inline]

evict_inodes+0x5f9/0x690 fs/inode.c:797

generic_shutdown_super+0x9d/0x2d0 fs/super.c:627

kill_block_super+0x44/0x90 fs/super.c:1696

kill_f2fs_super+0x344/0x690 fs/f2fs/super.c:4898

deactivate_locked_super+0xc4/0x130 fs/super.c:473

cleanup_mnt+0x41f/0x4b0 fs/namespace.c:1373

task_work_run+0x24f/0x310 kernel/task_work.c:228

ptrace_notify+0x2d2/0x380 kernel/signal.c:2402

ptrace_report_syscall include/linux/ptrace.h:415 [inline]

ptrace_report_syscall_exit include/linux/ptrace.h:477 [inline]

syscall_exit_work+0xc6/0x190 kernel/entry/common.c:173

syscall_exit_to_user_mode_prepare kernel/entry/common.c:200 [inline]

__syscall_exit_to_user_mode_work kernel/entry/common.c:205 [inline]

syscall_exit_to_user_mode+0x279/0x370 kernel/entry/common.c:218

do_syscall_64+0x100/0x230 arch/x86/entry/common.c:89

entry_SYSCALL_64_after_hwframe+0x77/0x7f

RIP: 0010:f2fs_evict_inode+0x1598/0x15c0 fs/f2fs/inode.c:896

Online repaire on corrupted directory in f2fs_lookup() can generate

dirty data/meta while racing w/ readonly remount, it may leave dirty

inode after filesystem becomes readonly, however, checkpoint() will

skips flushing dirty inode in a state of readonly mode, result in

above panic.

Let's get rid of online repaire in f2fs_lookup(), and leave the work

to fsck.f2fs.

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Affected software

AZL-50788 is recorded against 1 package.

  • kernel (fixed in 5.15.173.1-1)

Timeline and source

Published on 21 October 2024 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

nvd.nist.gov (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-10-21
Updated 2026-08-12
Modified 2026-04-21
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 5.15.173.1-1

Similar Threats

Free Vulnerability Check

Is your site affected by AZL-50788?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-50788 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.