cbcvebase.
CVE-2024-53136
published 2024-12-04

CVE-2024-53136: In the Linux kernel, the following vulnerability has been resolved: mm: revert "mm: shmem: fix data-race in shmem_getattr()" Revert d949d1d14fa2 ("mm: shmem…

PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.42%
35.1th percentile
In the Linux kernel, the following vulnerability has been resolved: mm: revert "mm: shmem: fix data-race in shmem_getattr()" Revert d949d1d14fa2 ("mm: shmem: fix data-race in shmem_getattr()") as suggested by Chuck [1]. It is causing deadlocks when accessing tmpfs over NFS. As Hugh commented, "added just to silence a syzbot sanitizer splat: added where there has never been any practical problem".

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux>= 3d9528484480e8f4979b3a347930ed383be99f89 < d3f9d88c2c03b2646ace336236adca19f7697bd3d3f9d88c2c03b2646ace336236adca19f7697bd3
linuxlinux>= 4.19.323 < 4.19.3254.19.325
linuxlinux>= 5.10.229 < 5.10.2315.10.231
linuxlinux>= 5.15.171 < 5.15.1745.15.174
linuxlinux>= 5.4.285 < 5.4.2875.4.287
linuxlinux>= 6.1.116 < 6.1.1196.1.119
linuxlinux>= 6.11.7 < 6.11.106.11.10
linuxlinux>= 6.6.60 < 6.6.636.6.63
linuxlinux>= 7cc30ada84323be19395094d567579536e0d187e < a3c65022d89d5baa2cea8e87a6de983ea305f14ca3c65022d89d5baa2cea8e87a6de983ea305f14c
linuxlinux>= 82cae1e30bd940253593c2d4f16d88343d1358f4 < 5874c1150e77296565ad6e495ef41fbf87570d145874c1150e77296565ad6e495ef41fbf87570d14
linuxlinux>= 9fb9703cd43ee20a6de8ccdef991677b7274cec0 < 36b537e8f302f670c7cf35d88a3a294443e32d5236b537e8f302f670c7cf35d88a3a294443e32d52
linuxlinux>= bda1a99a0dd644f31a87d636ac624eeb975cb65a < 57cc8d253099d1b8627f0fb487ee011d9158ccc957cc8d253099d1b8627f0fb487ee011d9158ccc9
linuxlinux>= d949d1d14fa281ace388b1de978e8f2cd52875cf < d1aa0c04294e29883d65eac6c2f72fe95cc7c049d1aa0c04294e29883d65eac6c2f72fe95cc7c049
linuxlinux>= edd1f905050686fdc4cfe233d818469fdf7d5ff8 < 64e67e8694252c1bf01b802ee911be3fee62c36b64e67e8694252c1bf01b802ee911be3fee62c36b
linuxlinux>= ffd56612566bc23877c8f45def2801f3324a222a < 901dc2ad7c3789fa87dc3956f6697c5d62d5cf7e901dc2ad7c3789fa87dc3956f6697c5d62d5cf7e
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.10-16.11.10-1
linuxlinux_kernel>= 0 < 6.11.10-16.11.10-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 4.19.323 < 4.19.3254.19.325
linuxlinux_kernel>= 5.10.229 < 5.115.11

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.