CVE-2024-38583·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix use-after-free of timer for log writer thread Patch series "nilfs2: fix log writer related issues". This bug fix series covers three nilfs2 log writer-related issues, including a timer use-after-free issue and potential deadlock issue on unmount, and a potential freeze issue in event synchronization found during their analysis. Details are described in each commit log. This patch (of 3): A use-after-free issue has been reported regarding the timer sc_timer on the nilfs_sc_info structure. The problem is that even though it is used to wake up a sleeping log writer thread, sc_timer is not shut down until the nilfs_sc_info structure is about to be freed, and is used regardless of the thread's lifetime. Fix this issue by limiting the use of sc_timer only while the log writer thread is alive.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.9.3
- Published
- 2024-06-19
Affected versions
From: 6.9
Until: 6.9.3
Fixed in: 6.9.3
How to fix this CVE
Update your Linux kernel to version 6.9.3 or later to resolve a use-after-free vulnerability in the NILFS2 filesystem's log writer timer mechanism. This flaw allows the sc_timer to be accessed after the log writer thread has terminated, potentially causing system instability. Kernel updates should be applied promptly and followed by a system reboot to take effect.
sudo dnf check-update kernel && sudo dnf upgrade kernel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version by running `uname -r` and verify if it falls in the 6.9.x range (affected: 6.9 to 6.9.2)
- Step 2: Confirm NILFS2 filesystem usage with `mount | grep nilfs2` or `lsblk -f | grep nilfs2`
- Step 3: Monitor system logs for kernel warnings or panics related to timers using `journalctl -b | grep -i 'use.after.free\|nilfs\|timer'`
- Step 4: After patching, verify the new kernel version with `uname -r` and confirm it is 6.9.3 or later
FAQ
What is CVE-2024-38583?
CVE-2024-38583 is a use-after-free vulnerability in the Linux NILFS2 filesystem log writer component. The sc_timer persists and can be accessed even after the log writer thread terminates, leading to potential memory corruption and system crashes.
Is CVE-2024-38583 being actively exploited?
No, CVE-2024-38583 is not listed as actively exploited in the CISA Known Exploited Vulnerabilities catalog, and no public exploits are currently available.
What versions of Kernel are affected by CVE-2024-38583?
Linux kernel versions 6.9 through 6.9.2 are affected. Kernel 6.9.3 and later versions include the fix.
How do I check if my server is vulnerable to CVE-2024-38583?
Run `uname -r` to see your kernel version. If it shows 6.9.0, 6.9.1, or 6.9.2 and your system uses NILFS2 filesystems (check with `mount | grep nilfs2`), your system is vulnerable and requires patching.
Does Defensia detect CVE-2024-38583?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server running versions 6.9 through 6.9.2, CVE-2024-38583 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/2f12b2c03c5dae1a0de0a9e5853177e3d6eee3c6
- https://git.kernel.org/stable/c/67fa90d4a2ccd9ebb0e1e168c7d0b5d0cf3c7148
- https://git.kernel.org/stable/c/68e738be5c518fc3c4e9146b66f67c8fee0135fb
- https://git.kernel.org/stable/c/822ae5a8eac30478578a75f7e064f0584931bf2d
- https://git.kernel.org/stable/c/82933c84f188dcfe89eb26b0b48ab5d1ca99d164
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-38583. Free for 1 server.
Get started free