CVE-2024-40998: ext4: fix uninitialized ratelimit_state->lock access in __ext4_fill_super()
ext4: fix uninitialized ratelimitstate->lock access in ext4fillsuper()
Other sources
Linux Kernel is vulnerable to a denial of service, caused by uninitialized Ratelimitstate->Lock Access in ext4fillsuper(). By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40998?
CVE-2024-40998 has a medium severity rating due to its potential impact on system stability.
How do I fix CVE-2024-40998?
To fix CVE-2024-40998, upgrade your kernel to version 6.6.36 or later for Red Hat or to version 5.10.223-1 or later for Debian.
What systems are affected by CVE-2024-40998?
CVE-2024-40998 affects certain versions of the Linux kernel in both Red Hat and Debian distributions.
When was CVE-2024-40998 disclosed?
CVE-2024-40998 was disclosed in 2024 as a vulnerability in the Linux kernel related to uninitialized data access.
What components are impacted by CVE-2024-40998?
CVE-2024-40998 impacts the ext4 filesystem implementation in the Linux kernel.