VYPR
High severity7.8NVD Advisory· Published Jul 29, 2024· Updated Aug 4, 2026

CVE-2024-41049

CVE-2024-41049

Description

In the Linux kernel, the following vulnerability has been resolved:

filelock: fix potential use-after-free in posix_lock_inode

Light Hsieh reported a KASAN UAF warning in trace_posix_lock_inode(). The request pointer had been changed earlier to point to a lock entry that was added to the inode's list. However, before the tracepoint could fire, another task raced in and freed that lock.

Fix this by moving the tracepoint inside the spinlock, which should ensure that this doesn't happen.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

86

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.