๐Ÿ” CVE Alert

CVE-2024-53143

HIGH 7.8

fsnotify: Fix ordering of iput() and watched_objects decrement

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: fsnotify: Fix ordering of iput() and watched_objects decrement Ensure the superblock is kept alive until we're done with iput(). Holding a reference to an inode is not allowed unless we ensure the superblock stays alive, which fsnotify does by keeping the watched_objects count elevated, so iput() must happen before the watched_objects decrement. This can lead to a UAF of something like sb->s_fs_info in tmpfs, but the UAF is hard to hit because race orderings that oops are more likely, thanks to the CHECK_DATA_CORRUPTION() block in generic_shutdown_super(). Also, ensure that fsnotify_put_sb_watched_objects() doesn't call fsnotify_sb_watched_objects() on a superblock that may have already been freed, which would cause a UAF read of sb->s_fsnotify_info.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Dec 7, 2024
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
d2f277e26f521ccf6fb438463b41dba6123caabe < 45a8f8232a495221ed058191629f5c628f21601a d2f277e26f521ccf6fb438463b41dba6123caabe < 83af1cfa10d9aafdabd06b3655e07727f373b434 d2f277e26f521ccf6fb438463b41dba6123caabe < 21d1b618b6b9da46c5116c640ac4b1cc8d40d63a
Linux / Linux
6.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/45a8f8232a495221ed058191629f5c628f21601a git.kernel.org: https://git.kernel.org/stable/c/83af1cfa10d9aafdabd06b3655e07727f373b434 git.kernel.org: https://git.kernel.org/stable/c/21d1b618b6b9da46c5116c640ac4b1cc8d40d63a project-zero.issues.chromium.org: https://project-zero.issues.chromium.org/issues/379667898