PT-2025-3059 · Linux+5 · Linux Kernel+5

Published

2024-12-19

·

Updated

2025-06-09

·

CVE-2024-54680

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.74
Description A vulnerability in the Linux kernel has been resolved, which fixed a TCP timers deadlock after rmmod. The issue occurred due to manual setting of sk->sk net refcnt, which is technically incorrect and can cause a deadlock on tcp write timer(). The problem happens regardless of CONFIG NET NS REFCNT TRACKER and whether init net or other network namespaces are used. The vulnerability can be reproduced by running a reproducer from a specific commit and then removing the cifs module.
Recommendations For Linux kernel versions prior to 6.6.74, update to version 6.6.74 or later to resolve the issue. As a temporary workaround, consider avoiding the removal of the cifs module while the system is running to minimize the risk of exploitation. Restrict access to the vulnerable network namespaces to minimize the risk of exploitation. Avoid using the sk net refcnt variable manually, as it can cause a deadlock.
Note: The provided information does not include details about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.

Fix

Use After Free

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-1925
ALT-PU-2025-3483
ALT-PU-2025-3496
BDU:2025-15309
CVE-2024-54680
INFSA-2025_6966
MGASA-2025-0030
MGASA-2025-0032
OESA-2025-1204
OESA-2025-1205
OESA-2025-1282
OESA-2025-1283
OESA-2025-1284
OPENSUSE-SU-2025_0428-1
OPENSUSE-SU-2025_0499-1
OPENSUSE-SU-2025_0556-1
OPENSUSE-SU-2025_0557-1
OPENSUSE-SU-2025_0576-1
OPENSUSE-SU-2025_0577-1
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2025:0289-1
SUSE-SU-2025:0428-1
SUSE-SU-2025:0499-1
SUSE-SU-2025:0555-1
SUSE-SU-2025:0556-1
SUSE-SU-2025:0557-1
SUSE-SU-2025:0576-1
SUSE-SU-2025:0577-1
SUSE-SU-2025:0577-2
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0428-1
SUSE-SU-2025_0499-1
SUSE-SU-2025_0557-1
SUSE-SU-2025_0577-1
SUSE-SU-2025_0577-2
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu