CVE-2024-43859
CBL Mariner vulnerability analysis and mitigation

Overview

CVE-2024-43859 affects the Linux kernel's F2FS (Flash-Friendly File System) implementation. The vulnerability was discovered by chenyuwen and involves a NULL pointer dereference issue that occurs during the handling of preallocated blocks in the file system. The issue specifically manifests when inode.i_crypt_info is not properly initialized during certain mount operations (NVD).

Technical details

The vulnerability is caused by a NULL pointer dereference at virtual address 0x11 in the F2FS filesystem code path during mount operations. The issue occurs specifically in the sequence: mount -> f2fs_fill_super -> f2fs_disable_checkpoint -> f2fs_gc -> f2fs_iget -> f2fs_truncate, where inode.i_crypt_info is not properly initialized. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.5 (Medium) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

The vulnerability can lead to a kernel NULL pointer dereference, potentially resulting in a system crash or denial of service condition. The impact is limited to local attacks and requires local user privileges to exploit (NVD).

Exploitability

The vulnerability requires local access and low privileges to exploit. It has been confirmed to be exploitable through specific mount operations in the F2FS filesystem (Kernel Patch).

Mitigation and workarounds

The issue has been fixed in the Linux kernel by relocating the truncation of preallocated blocks to f2fs_file_open(), after fscrypt_file_open(). The fix has been backported to various kernel versions including Ubuntu 24.04 LTS (kernel 6.8.0-50.51) and other distributions. Users should update their systems to the patched kernel versions (Ubuntu).

Additional resources


SourceThis report was generated using AI

Related CBL Mariner vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68454HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-devel
NoYesAug 13, 2026
CVE-2026-73500HIGH8.7
  • etcd logoetcd
  • cert-manager-1.19
NoYesAug 12, 2026
CVE-2026-72817MEDIUM6.9
  • CBL Mariner logoCBL Mariner
  • osbuild-composer
NoYesAug 14, 2026
CVE-2026-72816MEDIUM6.9
  • CBL Mariner logoCBL Mariner
  • osbuild-composer
NoYesAug 14, 2026
CVE-2026-68450LOW1.9
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-modules
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management