---
title: "CVE-2024-8946\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2024-8946?format=md
keywords: index, follow
---

# CVE-2024-8946

Publication date 17 September 2024

Last updated 3 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.3 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2024-8946?format=md#impact-score)

Toggle side navigation

## Description

A vulnerability was found in MicroPython 1.23.0. It has been classified as
critical. Affected is the function mp\_vfs\_umount of the file extmod/vfs.c
of the component VFS Unmount Handler. The manipulation leads to heap-based
buffer overflow. It is possible to launch the attack remotely. The exploit
has been disclosed to the public and may be used. The name of the patch is
29943546343c92334e8518695a11fc0e2ceea68b. It is recommended to apply a
patch to fix this issue. In the VFS unmount process, the comparison between
the mounted path string and the unmount requested string is based solely on
the length of the unmount string, which can lead to a heap buffer overflow
read.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| micropython | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Fixed 1.22.1+ds-1ubuntu0.24.10.1 |
| 24.04 LTS noble | Fixed 1.22.1+ds-1ubuntu0.24.04.1~esm1  Ubuntu Pro |
| 22.04 LTS jammy | Fixed 1.17+ds-1.1ubuntu2+esm1  Ubuntu Pro |
| 20.04 LTS focal | Fixed 1.12-1ubuntu0.1~esm1  Ubuntu Pro |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.3 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | Low |
  | Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.3 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8946)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2024-8946)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2024-8946)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2024-8946)

### Related Ubuntu Security Notices (USN)

+ [USN-7472-1](https://usn.ubuntu.com/USN-7472-1)
+ Micropython vulnerabilities
+ 1 May 2025

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2024-8946>
* <https://github.com/micropython/micropython/issues/13006>
* <https://github.com/micropython/micropython/issues/13006#issuecomment-1820309455>
* <https://vuldb.com/?id.277764>
* <https://vuldb.com/?ctiid.277764>
* <https://vuldb.com/?submit.409312>
* <https://github.com/micropython/micropython/commit/29943546343c92334e8518695a11fc0e2ceea68b>
