{"id":"CVE-2024-26704","title":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix double-free of blocks due to wrong extents moved_len\n\nIn ext4_move_extents(), moved_len is only updated when all moves are\nsuccessfully executed, and only dis…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix double-free of blocks due to wrong extents moved_len\n\nIn ext4_move_extents(), moved_len is only updated when all moves are\nsuccessfully executed, and only dis…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-415"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 3.18, < 4.19.307","linux_kernel >= 4.20, < 5.4.269","linux_kernel >= 5.5, < 5.10.210","linux_kernel >= 5.11, < 5.15.149","linux_kernel >= 5.16, < 6.1.79","linux_kernel >= 6.2, < 6.6.18","linux_kernel >= 6.7, < 6.7.6","linux_kernel = 6.8","debian_linux = 10.0"],"patched":["linux_kernel 6.7.6"],"published":"2024-04-03","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-26704","references":[{"url":"https://git.kernel.org/stable/c/185eab30486ba3e7bf8b9c2e049c79a06ffd2bc1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2883940b19c38d5884c8626483811acf4d7e148f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55583e899a5357308274601364741a83e78d6ac4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/559ddacb90da1d8786dd8ec4fd76bbfa404eaef6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/afba9d11320dad5ce222ac8964caf64b7b4bedb1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/afbcad9ae7d6d11608399188f03a837451b6b3a1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4fbb89d722cbb16beaaea234b7230faaaf68c71","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d033a555d9a1cf53dbf3301af7199cc4a4c8f537","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/185eab30486ba3e7bf8b9c2e049c79a06ffd2bc1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/2883940b19c38d5884c8626483811acf4d7e148f","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/55583e899a5357308274601364741a83e78d6ac4","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/559ddacb90da1d8786dd8ec4fd76bbfa404eaef6","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/afba9d11320dad5ce222ac8964caf64b7b4bedb1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/afbcad9ae7d6d11608399188f03a837451b6b3a1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/b4fbb89d722cbb16beaaea234b7230faaaf68c71","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/d033a555d9a1cf53dbf3301af7199cc4a4c8f537","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00266,"epssPercentile":0.16398,"ingestedAt":"2026-08-05T10:46:48.111Z","slug":"CVE-2024-26704","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\next4: fix double-free of blocks due to wrong extents moved_len\n\nIn ext4_move_extents(), moved_len is only updated when all moves are\nsuccessfully executed, and only discards orig_inode and donor_inode\npreallocations when moved_len is not zero. When the loop fails to exit\nafter successfully moving some extents, moved_len is not updated and\nremains at 0, so it does not discard the preallocations.\n\nIf the moved extents overlap with the preallocated extents, the\noverlapped extents are freed twice in ext4_mb_release_inode_pa() and\next4_process_freed_data() (as described in commit 94d7c16cbbbd (\"ext4:\nFix double-free of blocks with EXT4_IOC_MOVE_EXT\")), and bb_free is\nincremented twice. Hence when trim is executed, a zero-division bug is\ntriggered in mb_update_avg_fragment_size() because bb_free is not zero\nand bb_fragments is zero.\n\nTherefore, update move_len after each extent move to avoid the issue.\n\n## Affected\n\n- `linux_kernel >= 3.18, < 4.19.307`\n- `linux_kernel >= 4.20, < 5.4.269`\n- `linux_kernel >= 5.5, < 5.10.210`\n- `linux_kernel >= 5.11, < 5.15.149`\n- `linux_kernel >= 5.16, < 6.1.79`\n- `linux_kernel >= 6.2, < 6.6.18`\n- `linux_kernel >= 6.7, < 6.7.6`\n- `linux_kernel = 6.8`\n- `debian_linux = 10.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.7.6`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}