CVE-2024-53136
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-53136 is a vulnerability in the Linux kernel related to a data race condition in the shmem_getattr() function. The issue was discovered in November 2024 and affects multiple versions of the Linux kernel including 4.19.323 through 4.19.325, 5.4.285, 5.10.229, 5.15.171, and various other versions (NVD).

Technical details

The vulnerability stems from a previous fix attempt (commit d949d1d14fa2) that was implemented to address a data race in shmem_getattr(). However, this fix introduced potential deadlocks when accessing tmpfs over NFS. The issue has a CVSS v3.1 base score of 4.7 (Medium) with a vector string of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local access required with high attack complexity (NVD).

Impact

The vulnerability can cause deadlocks in the system when accessing tmpfs over NFS. However, as noted by Hugh Dickins, the original issue this attempted to fix "has never been any practical problem" and was mainly implemented to silence a syzkaller bot sanitizer warning (Kernel Patch).

Mitigation and workarounds

The issue has been resolved by reverting the previous fix (commit d949d1d14fa2) that caused the deadlock problems. This reversion was suggested by Chuck Lever and received acknowledgment from Hugh Dickins. The fix has been implemented across multiple kernel versions through various patch commits (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management