In the Linux kernel, the following vulnerability has been resolved:
ubifs: Fix races between xattr_{set|get} and listxattr operations
UBIFS may occur some problems with concurrent xattr_{set|get} and listxattr operations, such as assertion failure, memory corruption, stale xattr value[1].
Fix it by importing a new rw-lock in @ubifs_inode to serilize write operations on xattr, concurrent read operations are still effective, just like ext4.
[1] https://lore.kernel.org/linux-mtd/[email protected]
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | May 21, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 21, 2024 |
| Ubuntu | — | Upgrade linux-awsUpgrade linux-oracle-5.4Upgrade linux-bluefieldUpgrade linux-aws-5.4Upgrade linux-raspiUpgrade linux-kvmUpgrade linux-azureUpgrade linux-raspi-5.4Upgrade linux-gkeopUpgrade linux-aws-fipsUpgrade linux-oracleUpgrade linux-gcp-5.4Upgrade linux-fipsUpgrade linux-gcp-fipsUpgrade linux-gcpUpgrade linux-azure-5.4Upgrade linux-azure-fipsUpgrade linuxUpgrade linux-hwe-5.4 | Nov 19, 2024 | May 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub