PT-2024-5910 · Linux+6 · Linux Kernel+6

Zhihao Cheng

·

Published

2024-08-13

·

Updated

2026-02-21

·

CVE-2024-45003

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The vulnerability is related to the dispose list function in the Linux kernel's vfs component. It is caused by incorrect resource cleanup or release, which can lead to a deadlock when the inode reclaiming process tries to destroy inodes marked with the I FREEING flag. This issue can occur when certain filesystems, such as ext4 with the ea inode feature or ubifs with xattr, perform inode lookups in the inode evicting callback function under the inode lru traversing context. The vulnerability can result in a denial-of-service (DoS) condition.
Technical details about exploitation include:
  • API Endpoints: None mentioned.
  • Vulnerable Parameters or Variables: i ea, i reg, ixa, ib, ia.
  • Function Names: prune icache sb, find inode fast, ext4 evict inode, ubifs jnl write inode, inode lru isolate, iget, iget locked, ext4 iget, ubifs iget.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-12535
ALT-PU-2024-12541
ALT-PU-2024-13979
ALT-PU-2024-14046
BDU:2024-06716
CVE-2024-45003
DLA-3912-1
DLA-4008-1
DSA-5782-1
MGASA-2024-0309
MGASA-2024-0310
OESA-2024-2181
OESA-2024-2182
OESA-2024-2183
OESA-2024-2185
OPENSUSE-SU-2024_3408-1
OPENSUSE-SU-2024_3551-1
OPENSUSE-SU-2024_3561-1
OPENSUSE-SU-2024_3564-1
OPENSUSE-SU-2024_3585-1
OPENSUSE-SU-2024_3587-1
OPENSUSE-SU-2024_3592-1
SUSE-SU-2024:3403-1
SUSE-SU-2024:3408-1
SUSE-SU-2024:3551-1
SUSE-SU-2024:3561-1
SUSE-SU-2024:3564-1
SUSE-SU-2024:3565-1
SUSE-SU-2024:3567-1
SUSE-SU-2024:3569-1
SUSE-SU-2024:3585-1
SUSE-SU-2024:3587-1
SUSE-SU-2024:3592-1
SUSE-SU-2025:20073-1
SUSE-SU-2025:20077-1
USN-7088-1
USN-7088-2
USN-7088-3
USN-7088-4
USN-7088-5
USN-7100-1
USN-7100-2
USN-7119-1
USN-7123-1
USN-7144-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7194-1
USN-7196-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu