Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: gfs2: fix double destroy_workqueue error When gfs2_fill_super() fails, destroy_workqueue() is called within gfs2_gl_hash_clear(), and the subsequent code path calls destroy_workqueue() on the same work queue again. This issue can be fixed by setting the work queue pointer to NULL after the first destroy_workqueue() call and checking for a NULL pointer before attempting to destroy the work queue again.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.11, < 6.11.3 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/6cb9df81a2c462b89d2f9611009ab43ae8717841Patch
- https://git.kernel.org/stable/c/a5336035728d77efd76306940d742a6f23debe68Patch
FAQ
What is CVE-2024-49956?
CVE-2024-49956 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: gfs2: fix double destroy_workqueue error When gfs2_fill_super() fails, destroy_workqueue() is called within gfs2_gl_hash_clear(), ...
How severe is CVE-2024-49956?
CVE-2024-49956 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-49956?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.