{"id":"DEBIAN-CVE-2024-43859","details":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to truncate preallocated blocks in f2fs_file_open()  chenyuwen reports a f2fs bug as below:  Unable to handle kernel NULL pointer dereference at virtual address 0000000000000011  fscrypt_set_bio_crypt_ctx+0x78/0x1e8  f2fs_grab_read_bio+0x78/0x208  f2fs_submit_page_read+0x44/0x154  f2fs_get_read_data_page+0x288/0x5f4  f2fs_get_lock_data_page+0x60/0x190  truncate_partial_data_page+0x108/0x4fc  f2fs_do_truncate_blocks+0x344/0x5f0  f2fs_truncate_blocks+0x6c/0x134  f2fs_truncate+0xd8/0x200  f2fs_iget+0x20c/0x5ac  do_garbage_collect+0x5d0/0xf6c  f2fs_gc+0x22c/0x6a4  f2fs_disable_checkpoint+0xc8/0x310  f2fs_fill_super+0x14bc/0x1764  mount_bdev+0x1b4/0x21c  f2fs_mount+0x20/0x30  legacy_get_tree+0x50/0xbc  vfs_get_tree+0x5c/0x1b0  do_new_mount+0x298/0x4cc  path_mount+0x33c/0x5fc  __arm64_sys_mount+0xcc/0x15c  invoke_syscall+0x60/0x150  el0_svc_common+0xb8/0xf8  do_el0_svc+0x28/0xa0  el0_svc+0x24/0x84  el0t_64_sync_handler+0x88/0xec  It is because inode.i_crypt_info is not initialized during below path: - mount  - f2fs_fill_super   - f2fs_disable_checkpoint    - f2fs_gc     - f2fs_iget      - f2fs_truncate  So, let's relocate truncation of preallocated blocks to f2fs_file_open(), after fscrypt_file_open().","modified":"2026-09-15T09:03:10.663111707Z","published":"2024-08-17T10:15:10.817Z","upstream":["CVE-2024-43859"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-43859"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.112-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-43859.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-43859.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-43859.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}