vulnerability

Amazon Linux AMI: CVE-2024-49960: Security patch for kernel (ALAS-2025-1966)

Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
Oct 21, 2024
Added
Mar 18, 2025
Modified
May 21, 2025

Description

In the Linux kernel, the following vulnerability has been resolved:



ext4: fix timer use-after-free on failed mount



Syzbot has found an ODEBUG bug in ext4_fill_super



The del_timer_sync function cancels the s_err_report timer,


which reminds about filesystem errors daily. We should


guarantee the timer is no longer active before kfree(sbi).



When filesystem mounting fails, the flow goes to failed_mount3,


where an error occurs when ext4_stop_mmpd is called, causing


a read I/O failure. This triggers the ext4_handle_error function


that ultimately re-arms the timer,


leaving the s_err_report timer active before kfree(sbi) is called.



Fix the issue by canceling the s_err_report timer after calling ext4_stop_mmpd.

Solution

amazon-linux-upgrade-kernel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.