In the Linux kernel, the following vulnerability has been resolved:
tmpfs: fix race on handling dquot rbtree
A syzkaller reproducer found a race while attempting to remove dquot information from the rb tree.
Fetching the rb_tree root node must also be protected by the dqopt->dqio_sem, otherwise, giving the right timing, shmem_release_dquot() will trigger a warning because it couldn't find a node in the tree, when the real reason was the root node changing before the search starts:
Thread 1 Thread 2 - shmem_release_dquot() - shmem_{acquire,release}_dquot()
- fetch ROOT - Fetch ROOT
- acquire dqio_sem - wait dqio_sem
- do something, triger a tree rebalance - release dqio_sem
- acquire dqio_sem - start searching for the node, but from the wrong location, missing the node, and triggering a warning.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-6.8.0-35-lowlatency-64kUpgrade linux-image-azureUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.8.0-1006-oracle-64kUpgrade linux-image-genericUpgrade linux-image-raspiUpgrade linux-image-6.8.0-35-generic-64kUpgrade linux-image-6.8.0-35-genericUpgrade linux-image-azure-fdeUpgrade linux-image-lowlatency-64kUpgrade linux-image-6.8.0-1006-ibmUpgrade linux-image-6.8.0-35-lowlatencyUpgrade linux-image-awsUpgrade linux-image-6.8.0-1008-gcpUpgrade linux-image-oracle-64kUpgrade linux-image-6.8.0-1008-azure-fdeUpgrade linux-image-6.8.0-1006-oemUpgrade linux-image-generic-64kUpgrade linux-image-gkeUpgrade linux-image-6.8.0-1009-awsUpgrade linux-image-6.8.0-1004-gkeUpgrade linux-image-6.8.0-1006-oracleUpgrade linux-image-generic-lpaeUpgrade linux-image-oem-24.04aUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-oracleUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-kvmUpgrade linux-image-ibm-classicUpgrade linux-image-lowlatencyUpgrade linux-image-6.8.0-1008-azureUpgrade linux-image-gcpUpgrade linux-image-ibmUpgrade linux-image-6.8.0-1005-raspiUpgrade linux-image-oem-24.04Upgrade linux-image-virtual | Jul 1, 2024 | May 1, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub