CVE-2024-56780
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-56780 is a vulnerability in the Linux kernel's quota system that was discovered and disclosed in January 2025. The issue affects multiple versions of the Linux kernel, including versions 4.19.295 through 6.13, and involves a race condition in the quota writeback functionality (NVD).

Technical details

The vulnerability occurs in the quota subsystem's writeback functionality, specifically in the path involving freeze_super(), sync_filesystem(), ext4_sync_fs(), and dquot_writeback_dquots() functions. The issue arises because the quota_release_work queue is not always flushed in this path, leading to a race condition. The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (MEDIUM) with a vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

When exploited, this vulnerability can result in a WARN_ON condition when the kernel attempts to flush the workqueue while the filesystem is frozen, causing transaction starts during a frozen state. This primarily affects system stability and can lead to system warnings and potential denial of service conditions (Kernel Patch).

Mitigation and workarounds

The vulnerability has been patched in the Linux kernel by adding code to flush the workqueue during dquot_writeback_dquots(), ensuring no pending workitems remain after freeze. The fix has been backported to multiple stable kernel versions, including 4.19, 5.4, 5.10, 5.15, 6.1, and others (Debian LTS).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • bpftool
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-nvidia-6.14
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • linux-oracle-6.14
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-devel
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-debug-devel
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management