{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-47669", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-09-30T16:00:12.936Z", "datePublished": "2024-10-09T14:14:01.139Z", "dateUpdated": "2026-08-05T11:39:18.642Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:39:18.642Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix state management in error path of log writing function\n\nAfter commit a694291a6211 (\"nilfs2: separate wait function from\nnilfs_segctor_write\") was applied, the log writing function\nnilfs_segctor_do_construct() was able to issue I/O requests continuously\neven if user data blocks were split into multiple logs across segments,\nbut two potential flaws were introduced in its error handling.\n\nFirst, if nilfs_segctor_begin_construction() fails while creating the\nsecond or subsequent logs, the log writing function returns without\ncalling nilfs_segctor_abort_construction(), so the writeback flag set on\npages/folios will remain uncleared. This causes page cache operations to\nhang waiting for the writeback flag. For example,\ntruncate_inode_pages_final(), which is called via nilfs_evict_inode() when\nan inode is evicted from memory, will hang.\n\nSecond, the NILFS_I_COLLECTED flag set on normal inodes remain uncleared. \nAs a result, if the next log write involves checkpoint creation, that's\nfine, but if a partial log write is performed that does not, inodes with\nNILFS_I_COLLECTED set are erroneously removed from the \"sc_dirty_files\"\nlist, and their data and b-tree blocks may not be written to the device,\ncorrupting the block mapping.\n\nFix these issues by uniformly calling nilfs_segctor_abort_construction()\non failure of each step in the loop in nilfs_segctor_do_construct(),\nhaving it clean up logs and segment usages according to progress, and\ncorrecting the conditions for calling nilfs_redirty_inodes() to ensure\nthat the NILFS_I_COLLECTED flag is cleared." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H", "baseScore": 7.3, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The defect is in the nilfs2 segment constructor, reached through ordinary local filesystem operations — write(2) on a mounted nilfs2 plus fdatasync(2)/sync(2), or the background writeback/segctor thread. No network protocol handler processes remote data on this path.\nAC:L - There is no race and no memory-layout dependency; the attacker deterministically creates both required conditions by writing a file larger than one segment (forcing a second log iteration in SC_LSEG_DSYNC mode) while having exhausted the filesystem's clean segments, so nilfs_sufile_alloc() returns -ENOSPC inside the second nilfs_segctor_begin_construction(). Memory pressure (-ENOMEM from nilfs_segbuf_new) is an equally attacker-controllable alternative trigger.\nPR:L - Any unprivileged local user with write access to an already-mounted nilfs2 filesystem can reach nilfs_segctor_do_construct() via plain writes and fdatasync — no capability, ioctl, or mount privilege is checked on this path (CAP_SYS_ADMIN is only needed for the unrelated GC ioctl).\nUI:N - On a system already using nilfs2 (flash/removable media, udisks-automounted volumes) the attacker drives the entire sequence with their own file I/O and the kernel's own writeback thread. No action by a separate victim user is required.\nS:U - The stuck writeback state, the hung tasks, and the filesystem corruption are all confined to the kernel and filesystem of the same system; no VM, IOMMU, or sandbox security boundary is crossed.\nC:L - Dropping inodes from sc_dirty_files without writing their data and b-tree blocks corrupts the block mapping, so an inode's bmap can retain virtual block numbers whose DAT entries are stale or recycled by the segment cleaner, causing later reads to return blocks belonging to other users' files. The exposure is stale on-disk filesystem data the attacker cannot select, not an arbitrary kernel memory read.\nI:H - sc_dirty_files holds every dirty inode on the filesystem, not just the attacker's, so the uncleared NILFS_I_COLLECTED flag causes arbitrary inodes' data and b-tree blocks to be silently discarded while they are marked as written, corrupting the on-disk block mapping. This is persistent, unrecoverable filesystem metadata corruption with direct serious consequence — silent data loss across users and an inconsistent filesystem that can trigger nilfs_error() (forced read-only, or panic under errors=panic).\nA:H - The writeback flag left set on file-data and b-tree folios is never cleared, so folio_wait_writeback() callers — truncate_inode_pages_final() during inode eviction, sync/syncfs, umount, rewrite of the same page, and page reclaim/migration — block in uninterruptible sleep permanently, producing unkillable D-state tasks, hung-task warnings, unreclaimable pinned memory, and a system shutdown that never completes." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/nilfs2/segment.c" ], "versions": [ { "version": "a694291a6211537189c6080f77f63cdabfc9b63e", "lessThan": "40a2757de2c376ef8a08d9ee9c81e77f3c750adf", "status": "affected", "versionType": "git" }, { "version": "a694291a6211537189c6080f77f63cdabfc9b63e", "lessThan": "036441e8438b29111fa75008f0ce305fb4e83c0a", "status": "affected", "versionType": "git" }, { "version": "a694291a6211537189c6080f77f63cdabfc9b63e", "lessThan": "efdde00d4a1ef10bb71e09ebc67823a3d3ad725b", "status": "affected", "versionType": "git" }, { "version": "a694291a6211537189c6080f77f63cdabfc9b63e", "lessThan": "3e349d7191f0688fc9808ef24fd4e4b4ef5ca876", "status": "affected", "versionType": "git" }, { "version": "a694291a6211537189c6080f77f63cdabfc9b63e", "lessThan": "30562eff4a6dd35c4b5be9699ef61ad9f5f20a06", "status": "affected", "versionType": "git" }, { "version": "a694291a6211537189c6080f77f63cdabfc9b63e", "lessThan": "0a1a961bde4351dc047ffdeb2f1311ca16a700cc", "status": "affected", "versionType": "git" }, { "version": "a694291a6211537189c6080f77f63cdabfc9b63e", "lessThan": "74866c16ea2183f52925fa5d76061a1fe7f7737b", "status": "affected", "versionType": "git" }, { "version": "a694291a6211537189c6080f77f63cdabfc9b63e", "lessThan": "6576dd6695f2afca3f4954029ac4a64f82ba60ab", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/nilfs2/segment.c" ], "versions": [ { "version": "2.6.33", "status": "affected" }, { "version": "0", "lessThan": "2.6.33", "status": "unaffected", "versionType": "semver" }, { "version": "4.19.322", "lessThanOrEqual": "4.19.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.4.284", "lessThanOrEqual": "5.4.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.10.226", "lessThanOrEqual": "5.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.167", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.110", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.51", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.10.10", "lessThanOrEqual": "6.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.11", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.33", "versionEndExcluding": "4.19.322" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.33", "versionEndExcluding": "5.4.284" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.33", "versionEndExcluding": "5.10.226" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.33", "versionEndExcluding": "5.15.167" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.33", "versionEndExcluding": "6.1.110" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.33", "versionEndExcluding": "6.6.51" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.33", "versionEndExcluding": "6.10.10" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.33", "versionEndExcluding": "6.11" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/40a2757de2c376ef8a08d9ee9c81e77f3c750adf" }, { "url": "https://git.kernel.org/stable/c/036441e8438b29111fa75008f0ce305fb4e83c0a" }, { "url": "https://git.kernel.org/stable/c/efdde00d4a1ef10bb71e09ebc67823a3d3ad725b" }, { "url": "https://git.kernel.org/stable/c/3e349d7191f0688fc9808ef24fd4e4b4ef5ca876" }, { "url": "https://git.kernel.org/stable/c/30562eff4a6dd35c4b5be9699ef61ad9f5f20a06" }, { "url": "https://git.kernel.org/stable/c/0a1a961bde4351dc047ffdeb2f1311ca16a700cc" }, { "url": "https://git.kernel.org/stable/c/74866c16ea2183f52925fa5d76061a1fe7f7737b" }, { "url": "https://git.kernel.org/stable/c/6576dd6695f2afca3f4954029ac4a64f82ba60ab" } ], "title": "nilfs2: fix state management in error path of log writing function", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2024-10-10T13:20:56.031948Z", "id": "CVE-2024-47669", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-10-10T13:21:10.087Z" } }, { "title": "CVE Program Container", "references": [ { "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-11-03T22:20:34.709Z" } } ] } }