PT-2025-2979 · Linux+6 · Linux Kernel+6

Dario Weißer

·

Published

2024-12-16

·

Updated

2026-01-23

·

CVE-2024-53685

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.74
Description The issue concerns a denial of service (DoS) vulnerability in the Linux kernel. Specifically, when the ceph mdsc build path() function attempts to build a path longer than PATH MAX, it enters an endless loop, effectively blocking the task and making most of the machine unusable. This vulnerability is considered simple and effective. The retry mechanism in this function seems unnecessary and harmful. To address this, the function will now fail with ENAMETOOLONG instead of retrying.
Recommendations For Linux kernel versions prior to 6.6.74, update to version 6.6.74 or later to resolve the issue. As a temporary workaround, consider disabling the ceph mdsc build path() function until a patch is available. Restrict access to paths that could potentially exceed PATH MAX to minimize the risk of exploitation. Avoid using paths longer than PATH MAX in the affected ceph mdsc build path() function until the issue is resolved.

Exploit

Fix

DoS

Resource Exhaustion

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12026
CVE-2024-53685
DLA-4075-1
DLA-4076-1
DSA-5860-1
MGASA-2025-0030
MGASA-2025-0032
OESA-2026-1228
OESA-2026-1229
OPENSUSE-SU-2025_0428-1
OPENSUSE-SU-2025_0499-1
OPENSUSE-SU-2025_0557-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:0428-1
SUSE-SU-2025:0499-1
SUSE-SU-2025:0557-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0428-1
SUSE-SU-2025_0499-1
SUSE-SU-2025_0557-1
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7387-1
USN-7387-2
USN-7387-3
USN-7388-1
USN-7389-1
USN-7390-1
USN-7407-1
USN-7421-1
USN-7458-1
USN-7459-1
USN-7459-2
USN-7513-1
USN-7513-2
USN-7513-3
USN-7513-4
USN-7513-5
USN-7514-1
USN-7515-1
USN-7515-2
USN-7522-1
USN-7523-1
USN-7524-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu