Answer in brief
CVE-2024-49960 records a Unknown severity vulnerability in ext4: fix timer use-after-free on failed mount. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-49960 records a Unknown severity vulnerability in ext4: fix timer use-after-free on failed mount. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5e4f5138bd8522ebe231a137682d3857209a2c07 <7aac0c17a8cdf4a3236991c1e60435c6a984076c || >=618f003199c6188e01472b03cdbba227f1dc5f24 <22e9b83f0f33bc5a7a3181769d1dccbf021f5b04 || >=618f003199c6188e01472b03cdbba227f1dc5f24 <cf3196e5e2f36cd80dab91ffae402e13935724bc || >=618f003199c6188e01472b03cdbba227f1dc5f24 <9203817ba46ebba7c865c8de2aba399537b6e891 || >=618f003199c6188e01472b03cdbba227f1dc5f24 <fa78fb51d396f4f2f80f8e96a3b1516f394258be || >=618f003199c6188e01472b03cdbba227f1dc5f24 <b85569585d0154d4db1e4f9e3e6a4731d407feb0 || >=618f003199c6188e01472b03cdbba227f1dc5f24 <0ce160c5bdb67081a62293028dc85758a8efb22a || cecfdb9cf9a700d1037066173abac0617f6788df || eb7b40d9d3785f7a131fb0b1f89bb6efa46c1833 || >=5.10.51 <5.10.237 || >=5.12.18 <5.13 || >=5.13.3 <5.14 | 7aac0c17a8cdf4a3236991c1e60435c6a984076c, 22e9b83f0f33bc5a7a3181769d1dccbf021f5b04, cf3196e5e2f36cd80dab91ffae402e13935724bc, 9203817ba46ebba7c865c8de2aba399537b6e891, fa78fb51d396f4f2f80f8e96a3b1516f394258be, b85569585d0154d4db1e4f9e3e6a4731d407feb0, 0ce160c5bdb67081a62293028dc85758a8efb22a, 5.10.237, 5.13, 5.14 |
| Linux/Linuxgeneric | 5.14 | Not reported |
Published upstream
Oct 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ext4: fix timer use-after-free on failed mount Syzbot has found an ODEBUG bug in ext4_fill_super The del_timer_sync function cancels the s_err_report timer, which reminds about filesystem errors daily. We should guarantee the timer is no longer active before kfree(sbi). When filesystem mounting fails, the flow goes to failed_mount3, where an error occurs when ext4_stop_mmpd is called, causing a read I/O failure. This triggers the ext4_handle_error function that ultimately re-arms the timer, leaving the s_err_report timer active before kfree(sbi) is called. Fix the issue by canceling the s_err_report timer after calling ext4_stop_mmpd.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5e4f5138bd8522ebe231a137682d3857209a2c07 <7aac0c17a8cdf4a3236991c1e60435c6a984076c || >=618f003199c6188e01472b03cdbba227f1dc5f24 <22e9b83f0f33bc5a7a3181769d1dccbf021f5b04 || >=618f003199c6188e01472b03cdbba227f1dc5f24 <cf3196e5e2f36cd80dab91ffae402e13935724bc || >=618f003199c6188e01472b03cdbba227f1dc5f24 <9203817ba46ebba7c865c8de2aba399537b6e891 || >=618f003199c6188e01472b03cdbba227f1dc5f24 <fa78fb51d396f4f2f80f8e96a3b1516f394258be || >=618f003199c6188e01472b03cdbba227f1dc5f24 <b85569585d0154d4db1e4f9e3e6a4731d407feb0 || >=618f003199c6188e01472b03cdbba227f1dc5f24 <0ce160c5bdb67081a62293028dc85758a8efb22a || cecfdb9cf9a700d1037066173abac0617f6788df || eb7b40d9d3785f7a131fb0b1f89bb6efa46c1833 || >=5.10.51 <5.10.237 || >=5.12.18 <5.13 || >=5.13.3 <5.14 | 7aac0c17a8cdf4a3236991c1e60435c6a984076c, 22e9b83f0f33bc5a7a3181769d1dccbf021f5b04, cf3196e5e2f36cd80dab91ffae402e13935724bc, 9203817ba46ebba7c865c8de2aba399537b6e891, fa78fb51d396f4f2f80f8e96a3b1516f394258be, b85569585d0154d4db1e4f9e3e6a4731d407feb0, 0ce160c5bdb67081a62293028dc85758a8efb22a, 5.10.237, 5.13, 5.14 |
| Linux/Linuxgeneric | 5.14 | Not reported |
Published upstream
Oct 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ext4: fix timer use-after-free on failed mount Syzbot has found an ODEBUG bug in ext4_fill_super The del_timer_sync function cancels the s_err_report timer, which reminds about filesystem errors daily. We should guarantee the timer is no longer active before kfree(sbi). When filesystem mounting fails, the flow goes to failed_mount3, where an error occurs when ext4_stop_mmpd is called, causing a read I/O failure. This triggers the ext4_handle_error function that ultimately re-arms the timer, leaving the s_err_report timer active before kfree(sbi) is called. Fix the issue by canceling the s_err_report timer after calling ext4_stop_mmpd.
Quoted source text, attributed separately from HOL analysis.