cbcvebase.
CVE-2024-53685
published 2025-01-11

CVE-2024-53685: In the Linux kernel, the following vulnerability has been resolved: ceph: give up on paths longer than PATH_MAX If the full path to be built by…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ceph: give up on paths longer than PATH_MAX If the full path to be built by ceph_mdsc_build_path() happens to be longer than PATH_MAX, then this function will enter an endless (retry) loop, effectively blocking the whole task. Most of the machine becomes unusable, making this a very simple and effective DoS vulnerability. I cannot imagine why this retry was ever implemented, but it seems rather useless and harmful to me. Let's remove it and fail with ENAMETOOLONG instead.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux>= 9030aaf9bf0a1eee47a154c316c789e959638b0f < 0f2b2d9e881c90402dbe28f9ba831775b7992e1f0f2b2d9e881c90402dbe28f9ba831775b7992e1f
linuxlinux>= 9030aaf9bf0a1eee47a154c316c789e959638b0f < d42ad3f161a5a487f81915c406f46943c7187a0ad42ad3f161a5a487f81915c406f46943c7187a0a
linuxlinux>= 9030aaf9bf0a1eee47a154c316c789e959638b0f < e4b168c64da06954be5d520f6c16469b1cadc069e4b168c64da06954be5d520f6c16469b1cadc069
linuxlinux>= 9030aaf9bf0a1eee47a154c316c789e959638b0f < c47ed91156daf328601d02b58d52d9804da54108c47ed91156daf328601d02b58d52d9804da54108
linuxlinux>= 9030aaf9bf0a1eee47a154c316c789e959638b0f < 99a37ab76a315c8307eb5b0dc095d8ad9d8efeaa99a37ab76a315c8307eb5b0dc095d8ad9d8efeaa
linuxlinux>= 9030aaf9bf0a1eee47a154c316c789e959638b0f < 550f7ca98ee028a606aa75705a7e77b1bd11720f550f7ca98ee028a606aa75705a7e77b1bd11720f
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.8-16.12.8-1
linuxlinux_kernel>= 0 < 6.12.8-16.12.8-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 2.6.35 < 5.10.2345.10.234
linuxlinux_kernel>= 5.11 < 5.15.1775.15.177
linuxlinux_kernel>= 5.16 < 6.1.1256.1.125
linuxlinux_kernel>= 6.2 < 6.6.706.6.70
linuxlinux_kernel>= 6.7 < 6.12.76.12.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.