Answer in brief
CVE-2024-27058 records a Unknown severity vulnerability in tmpfs: fix race on handling dquot rbtree. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=eafc474e202978ac735c551d5ee1eb8c02e2be54 <c7077f43f30d817d10a9f8245e51576ac114b2f0 || >=eafc474e202978ac735c551d5ee1eb8c02e2be54 <617d55b90e73c7b4aa2733ca6cc3f9b72d1124bb || >=eafc474e202978ac735c551d5ee1eb8c02e2be54 <f82f184874d2761ebaa60dccf577921a0dbb3810 || >=eafc474e202978ac735c551d5ee1eb8c02e2be54 <0a69b6b3a026543bc215ccc866d0aea5579e6ce2 | c7077f43f30d817d10a9f8245e51576ac114b2f0, 617d55b90e73c7b4aa2733ca6cc3f9b72d1124bb, f82f184874d2761ebaa60dccf577921a0dbb3810, 0a69b6b3a026543bc215ccc866d0aea5579e6ce2 |
| Linux/Linuxgeneric | 6.6 | Not reported |
Published upstream
May 1, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: tmpfs: fix race on handling dquot rbtree A syzkaller reproducer found a race while attempting to remove dquot information from the rb tree. Fetching the rb_tree root node must also be protected by the dqopt->dqio_sem, otherwise, giving the right timing, shmem_release_dquot() will trigger a warning because it couldn't find a node in the tree, when the real reason was the root node changing before the search starts: Thread 1 Thread 2 - shmem_release_dquot() - shmem_{acquire,release}_dquot() - fetch ROOT - Fetch ROOT - acquire dqio_sem - wait dqio_sem - do something, triger a tree rebalance - release dqio_sem - acquire dqio_sem - start searching for the node, but from the wrong location, missing the node, and triggering a warning.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-27058 records a Unknown severity vulnerability in tmpfs: fix race on handling dquot rbtree. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=eafc474e202978ac735c551d5ee1eb8c02e2be54 <c7077f43f30d817d10a9f8245e51576ac114b2f0 || >=eafc474e202978ac735c551d5ee1eb8c02e2be54 <617d55b90e73c7b4aa2733ca6cc3f9b72d1124bb || >=eafc474e202978ac735c551d5ee1eb8c02e2be54 <f82f184874d2761ebaa60dccf577921a0dbb3810 || >=eafc474e202978ac735c551d5ee1eb8c02e2be54 <0a69b6b3a026543bc215ccc866d0aea5579e6ce2 | c7077f43f30d817d10a9f8245e51576ac114b2f0, 617d55b90e73c7b4aa2733ca6cc3f9b72d1124bb, f82f184874d2761ebaa60dccf577921a0dbb3810, 0a69b6b3a026543bc215ccc866d0aea5579e6ce2 |
| Linux/Linuxgeneric | 6.6 | Not reported |
Published upstream
May 1, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: tmpfs: fix race on handling dquot rbtree A syzkaller reproducer found a race while attempting to remove dquot information from the rb tree. Fetching the rb_tree root node must also be protected by the dqopt->dqio_sem, otherwise, giving the right timing, shmem_release_dquot() will trigger a warning because it couldn't find a node in the tree, when the real reason was the root node changing before the search starts: Thread 1 Thread 2 - shmem_release_dquot() - shmem_{acquire,release}_dquot() - fetch ROOT - Fetch ROOT - acquire dqio_sem - wait dqio_sem - do something, triger a tree rebalance - release dqio_sem - acquire dqio_sem - start searching for the node, but from the wrong location, missing the node, and triggering a warning.
Quoted source text, attributed separately from HOL analysis.