
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-37078 affects the NILFS2 file system in the Linux kernel. The vulnerability was discovered and disclosed on June 25, 2024. The issue occurs when destructive writes to a block device with nilfs2 mounted can trigger a kernel bug in the folio/page writeback start routine or writeback end routine (NVD).
The vulnerability stems from the log writer not waiting for ongoing folio/page writeback when starting a writeback for segment summary blocks or super root blocks that use the backing device's page cache. This results in an inconsistent writeback state, leading to a kernel bug at mm/page-writeback.c:3070 with an invalid opcode error (Kernel Commit).
When exploited, this vulnerability can cause a kernel bug, potentially resulting in system crashes and denial of service conditions on systems using the NILFS2 file system (NVD).
The vulnerability can be triggered through destructive writes to a block device on which nilfs2 is mounted. The issue requires local access to the system with the ability to perform write operations on NILFS2 mounted devices (Kernel Commit).
The issue has been fixed in various Linux kernel versions through patches that implement proper writeback flag waiting. The fix adds wait_on_page_writeback() calls before putting folios/pages into writeback state. Ubuntu has released fixes for multiple kernel versions including 5.15.0-121.131 for 22.04 LTS and 6.8.0-44.44 for 24.04 LTS (Ubuntu).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."