cbcvebase.
CVE-2024-47660
published 2024-10-09

CVE-2024-47660: In the Linux kernel, the following vulnerability has been resolved: fsnotify: clear PARENT_WATCHED flags lazily In some setups directories can have many…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.16%
5.6th percentile
In the Linux kernel, the following vulnerability has been resolved: fsnotify: clear PARENT_WATCHED flags lazily In some setups directories can have many (usually negative) dentries. Hence __fsnotify_update_child_dentry_flags() function can take a significant amount of time. Since the bulk of this function happens under inode->i_lock this causes a significant contention on the lock when we remove the watch from the directory as the __fsnotify_update_child_dentry_flags() call from fsnotify_recalc_mask() races with __fsnotify_update_child_dentry_flags() calls from __fsnotify_parent() happening on children. This can lead upto softlockup reports reported by users. Fix the problem by calling fsnotify_update_children_dentry_flags() to set PARENT_WATCHED flags only when parent starts watching children. When parent stops watching children, clear false positive PARENT_WATCHED flags lazily in __fsnotify_parent() for each accessed child.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 873feea09ebc980cbd3631b767356ce1eee65ec1 < 3f3ef1d9f66b93913ce2171120d9226b55acd41d3f3ef1d9f66b93913ce2171120d9226b55acd41d
linuxlinux>= 873feea09ebc980cbd3631b767356ce1eee65ec1 < f9a48bc3dd9099935751458a5bbbea4b7c28abc8f9a48bc3dd9099935751458a5bbbea4b7c28abc8
linuxlinux>= 873feea09ebc980cbd3631b767356ce1eee65ec1 < d8c42405fc3507cc43ba7e4986a773c3fc633f6ed8c42405fc3507cc43ba7e4986a773c3fc633f6e
linuxlinux>= 873feea09ebc980cbd3631b767356ce1eee65ec1 < fc1b1e135c3f72382f792e6c319fc088d5523ad5fc1b1e135c3f72382f792e6c319fc088d5523ad5
linuxlinux>= 873feea09ebc980cbd3631b767356ce1eee65ec1 < 7ef1d2e240c32b1f337a37232d037b07e3919e1a7ef1d2e240c32b1f337a37232d037b07e3919e1a
linuxlinux>= 873feea09ebc980cbd3631b767356ce1eee65ec1 < 172e422ffea20a89bfdc672741c1aad6fbb5044e172e422ffea20a89bfdc672741c1aad6fbb5044e
linuxlinux_kernel< 5.10.2265.10.226
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.11 < 5.15.1675.15.167
linuxlinux_kernel>= 5.16 < 6.1.1096.1.109
linuxlinux_kernel>= 6.2 < 6.6.506.6.50
linuxlinux_kernel>= 6.7 < 6.10.96.10.9

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.