CVE-2024-41086: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: bcachefs: Fix sb_field_downgrade validation - bch2_sb_downgrade_validate() wasn't checking for a downgrade entry extending past the end of the superblock section - for_each_downgrade_entry() is used in to_text() and needs to work on malformed input; it also was missing a check for a field extending past the end of the section

Affected products

  • Linux Linux Kernel: from 6.7.1, before 6.9.8 (fixed in 6.9.8); version 6.7 only

Published 2024-07-29. Last modified 2026-08-04.