CVE-2024-49958

Filesystem disclosure and corruption via reflink metadata overwrite

Published Oct 21, 2024 · Updated Aug 5, 2026

Improper input validation in Linux OCFS2 allows local users to read or corrupt filesystem data through a crafted reflink ioctl. ocfs2_reflink_xattr_inline reduces the destination inode's extent-record count to reserve inline xattr space after the reflink tree is attached, overwriting live extent records when more than 227 already exist. An unprivileged user needs a locally mounted OCFS2 filesystem, a crafted source file, and write access to a destination directory; exploitation can expose or overwrite disk blocks, remount the filesystem read-only, or panic clustered nodes.

CVSS severity7.8
High
EPSS probability0.27%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Improper input validation in Linux OCFS2 allows local users to read or corrupt filesystem data through a crafted reflink ioctl. ocfs2_reflink_xattr_inline reduces the destination inode's extent-record count to reserve inline xattr space after the reflink tree is attached, overwriting live extent records when more than 227 already exist. An unprivileged user needs a locally mounted OCFS2 filesystem, a crafted source file, and write access to a destination directory; exploitation can expose or overwrite disk blocks, remount the filesystem read-only, or panic clustered nodes.

The record

CVE
CVE-2024-49958
Published
Oct 21, 2024
Updated
Aug 5, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-20, T1485
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Oct 21, 2024CVE publishedPublication date reported by the CVE source.
  2. Aug 5, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=1926bf8ae44d80c9f50103f11fc4f17e2e2bf684
  2. Affected versionversion=1e7e4c9ae2a78a6791a2ca91a6a400f94855f01e
  3. Affected versionversion=26a849f49fb3347d126a0ed6611173f903374ef4
  4. Affected versionversion=3.0.87 <3.1
  5. Affected versionversion=3.10.2 <3.11
  6. Affected versionversion=3.11
  7. Affected versionversion=3.2.49 <3.3
  8. Affected versionversion=3.4.54 <3.5
  9. Affected versionversion=3.9.11 <3.10
  10. Affected versionversion=3a32958d2ac96070c53d04bd8e013c97b260b5e6
  11. Affected versionversion=93f26306db89c9dc37885b76a1082e6d54d23b16
  12. Affected versionversion=ef962df057aaafd714f5c22ba3de1be459571fdf <020f5c53c17f66c0a8f2d37dad27ace301b8d8a1
  13. Affected versionversion=ef962df057aaafd714f5c22ba3de1be459571fdf <5c2072f02c0d75802ec28ec703b7d43a0dd008b5
  14. Affected versionversion=ef962df057aaafd714f5c22ba3de1be459571fdf <5c9807c523b4fca81d3e8e864dabc8c806402121
  15. Affected versionversion=ef962df057aaafd714f5c22ba3de1be459571fdf <5ca60b86f57a4d9648f68418a725b3a7de2816b0
  16. Affected versionversion=ef962df057aaafd714f5c22ba3de1be459571fdf <637c00e06564a945e9d0edb3d78d362d64935f9f
  17. Affected versionversion=ef962df057aaafd714f5c22ba3de1be459571fdf <74364cb578dcc0b6c9109519d19cbe5a56afac9a
  18. Affected versionversion=ef962df057aaafd714f5c22ba3de1be459571fdf <96ce4c3537114d1698be635f5e36c62dc49df7a4
  19. Affected versionversion=ef962df057aaafd714f5c22ba3de1be459571fdf <9f9a8f3ac65b4147f1a7b6c05fad5192c0e3c3d9
  20. Affected versionversion=ef962df057aaafd714f5c22ba3de1be459571fdf <aac31d654a0a31cb0d2fa36ae694f4e164a52707

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=1926bf8ae44d80c9f50103f11fc4f17e2e2bf684; version=1e7e4c9ae2a78a6791a2ca91a6a400f94855f01e; version=26a849f49fb3347d126a0ed6611173f903374ef4; version=3.0.87 <3.1; version=3.10.2 <3.11; version=3.11; version=3.2.49 <3.3; version=3.4.54 <3.5; version=3.9.11 <3.10; version=3a32958d2ac96070c53d04bd8e013c97b260b5e6; version=93f26306db89c9dc37885b76a1082e6d54d23b16; version=ef962df057aaafd714f5c22ba3de1be459571fdf <020f5c53c17f66c0a8f2d37dad27ace301b8d8a1; version=ef962df057aaafd714f5c22ba3de1be459571fdf <5c2072f02c0d75802ec28ec703b7d43a0dd008b5; version=ef962df057aaafd714f5c22ba3de1be459571fdf <5c9807c523b4fca81d3e8e864dabc8c806402121; version=ef962df057aaafd714f5c22ba3de1be459571fdf <5ca60b86f57a4d9648f68418a725b3a7de2816b0; version=ef962df057aaafd714f5c22ba3de1be459571fdf <637c00e06564a945e9d0edb3d78d362d64935f9f; version=ef962df057aaafd714f5c22ba3de1be459571fdf <74364cb578dcc0b6c9109519d19cbe5a56afac9a; version=ef962df057aaafd714f5c22ba3de1be459571fdf <96ce4c3537114d1698be635f5e36c62dc49df7a4; version=ef962df057aaafd714f5c22ba3de1be459571fdf <9f9a8f3ac65b4147f1a7b6c05fad5192c0e3c3d9; version=ef962df057aaafd714f5c22ba3de1be459571fdf <aac31d654a0a31cb0d2fa36ae694f4e164a52707

Published CVSS scores

5.5NIST NVDCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
7.8Linux kernel CNACVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
5.5SUSECVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-20Improper Input Validation
T1485Data Destruction

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo