PT-2025-2814 · Linux+4 · Linux Kernel+4

Filipe Manana

+1

·

Published

2024-09-10

·

Updated

2026-05-26

·

CVE-2024-48875

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.74
Description: A vulnerability has been resolved in the Linux kernel, specifically in the btrfs module. The issue is related to a possible recursive locking detected when running fstests btrfs/011 with MKFS OPTIONS="-O rst". This could lead to a deadlock scenario. The vulnerability is caused by the btrfs module trying to acquire a lock that is already held by the task. Technical details about exploitation include the btrfs map block() function and the dev replace.rwsem lock.
Recommendations: To resolve the issue, update the Linux kernel to version 6.6.74 or later. As a temporary workaround, consider disabling the btrfs dev replace by ioctl() function until a patch is available. Restrict access to the btrfs map block() function to minimize the risk of exploitation. Avoid using the dev replace.rwsem lock in the affected API endpoints until the issue is resolved.

Exploit

Fix

Improper Locking

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17881
ALT-PU-2024-17897
ALT-PU-2025-12647
AZL-56216
AZL-56255
BDU:2025-06484
CVE-2024-48875
ECHO-6879-1955-7BFB
MGASA-2025-0030
MGASA-2025-0032
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Debian
Linuxmint
Linux Kernel
Ubuntu