CVE-2024-50277: Linux Kernel

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: dm: fix a crash if blk_alloc_disk fails If blk_alloc_disk fails, the variable md->disk is set to an error value. cleanup_mapped_device will see that md->disk is non-NULL and it will attempt to access it, causing a crash on this statement "md->disk->private_data = NULL;".

Affected products

  • Linux Linux Kernel: before 6.11.8 (fixed in 6.11.8); version 6.12 only

Published 2024-11-19. Last modified 2026-06-17.