CVE-2024-38570
A critical vulnerability in the Linux kernel’s GFS2 filesystem could allow an attacker to cause a use‑after‑free when a filesystem is unmounted. The flaw occurs when the kernel frees internal lock objects that are still in use, potentially leading to crashes or arbitrary code execution. The issue has been fixed in a recent kernel update.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel (any distribution using the GFS2 filesystem).
Real-world impact
An attacker could crash the system or execute arbitrary code by triggering a use‑after‑free during a GFS2 filesystem unmount, potentially compromising the host.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely with no authentication or user interaction, and it can lead to complete compromise of confidentiality, integrity, and availability.
What to do about it
- 01Update the Linux kernel to a version that includes the fix for CVE-2024-38570.
NVD-referenced vendor advisory
Timeline
- Jun 19, 2024 · Jun 19, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.