CVE-2024-37078
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-37078 affects the NILFS2 file system in the Linux kernel. The vulnerability was discovered and disclosed on June 25, 2024. The issue occurs when destructive writes to a block device with nilfs2 mounted can trigger a kernel bug in the folio/page writeback start routine or writeback end routine (NVD).

Technical details

The vulnerability stems from the log writer not waiting for ongoing folio/page writeback when starting a writeback for segment summary blocks or super root blocks that use the backing device's page cache. This results in an inconsistent writeback state, leading to a kernel bug at mm/page-writeback.c:3070 with an invalid opcode error (Kernel Commit).

Impact

When exploited, this vulnerability can cause a kernel bug, potentially resulting in system crashes and denial of service conditions on systems using the NILFS2 file system (NVD).

Exploitability

The vulnerability can be triggered through destructive writes to a block device on which nilfs2 is mounted. The issue requires local access to the system with the ability to perform write operations on NILFS2 mounted devices (Kernel Commit).

Mitigation and workarounds

The issue has been fixed in various Linux kernel versions through patches that implement proper writeback flag waiting. The fix adds wait_on_page_writeback() calls before putting folios/pages into writeback state. Ubuntu has released fixes for multiple kernel versions including 5.15.0-121.131 for 22.04 LTS and 6.8.0-44.44 for 24.04 LTS (Ubuntu).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-80904MEDIUM5.9
  • Linux Kernel logoLinux Kernel
  • linux-hwe-7.0
NoYesSep 04, 2026
CVE-2026-80905MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-7.0
NoYesSep 04, 2026
CVE-2026-80913MEDIUM4.4
  • Linux Kernel logoLinux Kernel
  • linux-intel-iotg-5.15
NoYesSep 04, 2026
CVE-2026-80912MEDIUM4.4
  • Linux Kernel logoLinux Kernel
  • linux-gcp-fips
NoYesSep 04, 2026
CVE-2026-80906NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-7.0
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management