Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <bc692002-3fae-4692-bdf8-f1aab1853217@gmail.com>
Date: Thu, 10 Apr 2025 17:51:36 -0400
From: Demi Marie Obenour <demiobenour@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE-2024-50217: Linux kernel: btrfs:
 Use-after-free of block device file in __btrfs_free_extra_devids()

On 4/10/25 8:22 AM, akendo@...ndo.eu wrote:
> Hey everyone,
> 
> Not too sure how or whom to ask about: But I saw that there is CVE-2024-50217 that affects every kernel since 4.8.
> 
> However, it is only fixed on more recent version of the linux kernel like 6.11 or 6.12. Any reason this wasn’t backported to older kernel versions?
Linux kernel patch backporting is best effort, sadly.
-- 
Sincerely,
Demi Marie Obenour (she/her/hers)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.