Skip to main content
EPSS 0.2%top 87%

CVE-2024-0775: Use After Free in Linux kernel

0
Medium
VulnerabilityCVE-2024-0775cvecve-2024-0775
Published: 01/22/2024 (01/22/2024, 13:03:09 UTC)
Source: CVE Database V5
Vendor/Project: Linux
Product: kernel

Description

A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while freeing the old quota file names before a potential failure, leading to a use-after-free.

CVSS v3.1

Score 6.7medium

Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected software

Affected versions
=0=4.15=4.20=5.5=5.11=5.16=6.2=6.34.154.205.55.115.166.26.3

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/11/2026, 13:51:52 UTC

Technical Analysis

CVE-2024-0775 is a use-after-free flaw in the __ext4_remount function within the ext4 filesystem code (fs/ext4/super.c) of the Linux kernel. This flaw occurs when the kernel frees old quota file names before a potential failure, leading to use-after-free conditions. The vulnerability allows a local user with high privileges to cause an information leak and potentially impact confidentiality, integrity, and availability. The CVSS 3.1 vector indicates local attack vector, low attack complexity, high privileges required, no user interaction, unchanged scope, and high impact on confidentiality, integrity, and availability. Red Hat's advisory notes that no mitigation meeting their criteria is currently available. The vulnerability affects several Linux kernel versions explicitly listed, and no known exploits are reported in the wild at this time.

Potential Impact

The vulnerability allows a local user with high privileges to cause an information leak by exploiting a use-after-free condition in the ext4 filesystem remount code. This can lead to unauthorized reading of memory, potential data corruption, denial of service via crashes, and possibly arbitrary code execution if exploited with malicious data. The CVSS score of 6.7 reflects a medium severity with high impact on confidentiality, integrity, and availability. No active exploitation has been reported.

Mitigation Recommendations

Currently, no official patch or mitigation that meets Red Hat's criteria for ease of use, deployment, applicability, or stability is available. Users should monitor Red Hat advisories for updates and consider upgrading to fixed versions once they are released. Red Hat recommends consulting with Technical Account Managers for tailored guidance. No temporary workarounds or mitigations are provided in the advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.1
Assigner Short Name
redhat
Date Reserved
2024-01-21T12:37:58.285Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2024-0775","vendor":"Red Hat"}]

Threat ID: 68e8557cba0e608b4fb1eed8

Added to database: 10/10/2025, 00:38:20 UTC

Last enriched: 08/11/2026, 13:51:52 UTC

Last updated: 09/10/2026, 19:36:47 UTC

Views: 206

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses