cbcvebase.
CVE-2024-36947
published 2024-05-30

CVE-2024-36947: In the Linux kernel, the following vulnerability has been resolved: qibfs: fix dentry leak simple_recursive_removal() drops the pinning references to all…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.48%
38.8th percentile
In the Linux kernel, the following vulnerability has been resolved: qibfs: fix dentry leak simple_recursive_removal() drops the pinning references to all positives in subtree. For the cases when its argument has been kept alive by the pinning alone that's exactly the right thing to do, but here the argument comes from dcache lookup, that needs to be balanced by explicit dput(). Fucked-up-by: Al Viro

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= e41d237818598c0b17458b4d0416b091a7959e55 < 24dd9b08df718f20ccf2dd1519909fefd8c233ee24dd9b08df718f20ccf2dd1519909fefd8c233ee
linuxlinux>= e41d237818598c0b17458b4d0416b091a7959e55 < bd8f78c71defbcb7a9ed331e7f287507df972b00bd8f78c71defbcb7a9ed331e7f287507df972b00
linuxlinux>= e41d237818598c0b17458b4d0416b091a7959e55 < db71ca93259dd1078bcfea3afafde2143cfc2da7db71ca93259dd1078bcfea3afafde2143cfc2da7
linuxlinux>= e41d237818598c0b17458b4d0416b091a7959e55 < 02ee394a5d899d9bd2f0759382e9481cab6166f802ee394a5d899d9bd2f0759382e9481cab6166f8
linuxlinux>= e41d237818598c0b17458b4d0416b091a7959e55 < aa23317d0268b309bb3f0801ddd0d61813ff5afbaa23317d0268b309bb3f0801ddd0d61813ff5afb
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.13 < 5.15.1595.15.159
linuxlinux_kernel>= 5.16 < 6.1.916.1.91
linuxlinux_kernel>= 6.2 < 6.6.316.6.31
linuxlinux_kernel>= 6.7 < 6.8.106.8.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.