CVE-2024-26871

Source
https://cve.org/CVERecord?id=CVE-2024-26871
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26871.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-26871
Downstream
Published
2024-04-17T10:27:31.396Z
Modified
2026-03-14T12:27:42.576997Z
Summary
f2fs: fix NULL pointer dereference in f2fs_submit_page_write()
Details

In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix NULL pointer dereference in f2fssubmitpage_write()

BUG: kernel NULL pointer dereference, address: 0000000000000014 RIP: 0010:f2fssubmitpagewrite+0x6cf/0x780 [f2fs] Call Trace: <TASK> ? showregs+0x6e/0x80 ? __die+0x29/0x70 ? pagefaultoops+0x154/0x4a0 ? prbreadvalid+0x20/0x30 ? _irqworkqueuelocal+0x39/0xd0 ? irqworkqueue+0x36/0x70 ? douseraddrfault+0x314/0x6c0 ? excpagefault+0x7d/0x190 ? asmexcpagefault+0x2b/0x30 ? f2fssubmitpagewrite+0x6cf/0x780 [f2fs] ? f2fssubmitpagewrite+0x736/0x780 [f2fs] dowritepage+0x50/0x170 [f2fs] f2fsoutplacewritedata+0x61/0xb0 [f2fs] f2fsdowritedatapage+0x3f8/0x660 [f2fs] f2fswritesingledatapage+0x5bb/0x7a0 [f2fs] f2fswritecachepages+0x3da/0xbe0 [f2fs] ... It is possible that other threads have added this fio to io->bio and submitted the io->bio before entering f2fssubmitpagewrite(). At this point io->bio = NULL. If isendzoneblkaddr(sbi, fio->newblkaddr) of this fio is true, then an NULL pointer dereference error occurs at bioget(io->bio). The original code for determining zone end was after "out:", which would have missed some fio who is zone end. I've moved this code before "skip:" to make sure it's done for each fio.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26871.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e067dc3c6b9c419bac43c6a0be2d85f44681f863
Fixed
8e2ea8b04cb8d976110c4568509e67d6a39b2889
Fixed
4c122a32582b67bdd44ca8d25f894ee2dc54f566
Fixed
6d102382a11d5e6035f6c98f6e508a38541f7af3
Fixed
c2034ef6192a65a986a45c2aa2ed05824fdc0e9f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26871.json"