CVE-2024-50272: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: filemap: Fix bounds checking in filemap_read() If the caller supplies an iocb->ki_pos value that is close to the filesystem upper limit, and an iterator with a count that causes us to overflow that limit, then filemap_read() enters an infinite loop. This behaviour was discovered when testing xfstests generic/525 with the "localio" optimisation for loopback NFS mounts.

Affected products

  • Linux Linux Kernel: from 3.16.40, before 3.17 (fixed in 3.17); from 4.7.10, before 4.8 (fixed in 4.8); from 4.8.4, before 4.9 (fixed in 4.9); from 4.9, before 6.1.117 (fixed in 6.1.117); from 6.2, before 6.6.61 (fixed in 6.6.61); from 6.7, before 6.11.8 (fixed in 6.11.8); …

Published 2024-11-19. Last modified 2026-06-17.