CVE-2024-49900 is an uninitialized value vulnerability in the Linux kernel's JFS filesystem, specifically within the ea_buffer structure. This flaw, identified by syzbot, can lead to uninitialized memory access during LZO compression, affecting systems running the Linux kernel. With a CVSS score of 7.1 (HIGH), successful exploitation could result in high confidentiality and availability impacts, though it requires local access and low privileges. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.10.227CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.168CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.113CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.55CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.10.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025CVE-2024-49900
Dec 10, 2024CVE-2024-49900
Nov 12, 2024kernel: jfs: Fix uninit-value access of new_ea in ea_buffer
Oct 21, 2024jfs: Fix uninit-value access of new_ea in ea_buffer
Oct 8, 2024