# CVE-2024-42079

## Summary

- **CVE ID:** CVE-2024-42079
- **Severity:** MEDIUM
- **CVSS Score:** 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** N/A
- **Published:** Jul 29, 2024
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

gfs2: Fix NULL pointer dereference in gfs2_log_flush

In gfs2_jindex_free(), set sdp->sd_jdesc to NULL under the log flush
lock to provide exclusion against gfs2_log_flush().

In gfs2_log_flush(), check if sdp->sd_jdesc is non-NULL before
dereferencing it.  Otherwise, we could run into a NULL pointer
dereference when outstanding glock work races with an unmount
(glock_work_func -> run_queue -> do_xmote -> inode_go_sync ->
gfs2_log_flush).

## Affected Products

- Linux — Linux (82218943058d5e3fe692a38b5a549479738dab33)
- Linux — Linux (5.12)
- Linux — Linux (0)
- Linux — Linux (5.15.200)
- Linux — Linux (6.1.162)
- Linux — Linux (6.6.37)
- Linux — Linux (6.9.8)
- Linux — Linux (6.10)

## References

- [CNA](https://git.kernel.org/stable/c/c3c5cfa3170c0940bc66a142859caac07d19b9d6)
- [CNA](https://git.kernel.org/stable/c/5f6a84cfb33b34610623857bd93919dcb661e29b)
- [CNA](https://git.kernel.org/stable/c/3429ef5f50909cee9e498c50f0c499b9397116ce)
- [CNA](https://git.kernel.org/stable/c/f54f9d5368a4e92ede7dd078a62788dae3a7c6ef)
- [CNA](https://git.kernel.org/stable/c/35264909e9d1973ab9aaa2a1b07cda70f12bb828)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 18.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._