Answer in brief
CVE-2024-27389 records a Unknown severity vulnerability in pstore: inode: Only d_invalidate() is needed. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=609e28bb139e53621521130f0d4aea27a725d465 <d0ee2a8adb6673382cce8a4280e1ca0849b3b783 || >=609e28bb139e53621521130f0d4aea27a725d465 <db6e5e16f1ee9e3b01d2f71c7f0ba945f4bf0f4e || >=609e28bb139e53621521130f0d4aea27a725d465 <4cdf9006fc095af71da80e9b5f48a32e991b9ed3 || >=609e28bb139e53621521130f0d4aea27a725d465 <cb9e802e49c24eeb3af35e9e8c04d526f35f112a || >=609e28bb139e53621521130f0d4aea27a725d465 <340682ed1932b8e3bd0bfc6c31a0c6354eb57cc6 || >=609e28bb139e53621521130f0d4aea27a725d465 <a43e0fc5e9134a46515de2f2f8d4100b74e50de3 | d0ee2a8adb6673382cce8a4280e1ca0849b3b783, db6e5e16f1ee9e3b01d2f71c7f0ba945f4bf0f4e, 4cdf9006fc095af71da80e9b5f48a32e991b9ed3, cb9e802e49c24eeb3af35e9e8c04d526f35f112a, 340682ed1932b8e3bd0bfc6c31a0c6354eb57cc6, a43e0fc5e9134a46515de2f2f8d4100b74e50de3 |
| Linux/Linuxgeneric | 5.8 | Not reported |
Published upstream
May 1, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: pstore: inode: Only d_invalidate() is needed Unloading a modular pstore backend with records in pstorefs would trigger the dput() double-drop warning: WARNING: CPU: 0 PID: 2569 at fs/dcache.c:762 dput.part.0+0x3f3/0x410 Using the combo of d_drop()/dput() (as mentioned in Documentation/filesystems/vfs.rst) isn't the right approach here, and leads to the reference counting problem seen above. Use d_invalidate() and update the code to not bother checking for error codes that can never happen. ---
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-27389 records a Unknown severity vulnerability in pstore: inode: Only d_invalidate() is needed. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=609e28bb139e53621521130f0d4aea27a725d465 <d0ee2a8adb6673382cce8a4280e1ca0849b3b783 || >=609e28bb139e53621521130f0d4aea27a725d465 <db6e5e16f1ee9e3b01d2f71c7f0ba945f4bf0f4e || >=609e28bb139e53621521130f0d4aea27a725d465 <4cdf9006fc095af71da80e9b5f48a32e991b9ed3 || >=609e28bb139e53621521130f0d4aea27a725d465 <cb9e802e49c24eeb3af35e9e8c04d526f35f112a || >=609e28bb139e53621521130f0d4aea27a725d465 <340682ed1932b8e3bd0bfc6c31a0c6354eb57cc6 || >=609e28bb139e53621521130f0d4aea27a725d465 <a43e0fc5e9134a46515de2f2f8d4100b74e50de3 | d0ee2a8adb6673382cce8a4280e1ca0849b3b783, db6e5e16f1ee9e3b01d2f71c7f0ba945f4bf0f4e, 4cdf9006fc095af71da80e9b5f48a32e991b9ed3, cb9e802e49c24eeb3af35e9e8c04d526f35f112a, 340682ed1932b8e3bd0bfc6c31a0c6354eb57cc6, a43e0fc5e9134a46515de2f2f8d4100b74e50de3 |
| Linux/Linuxgeneric | 5.8 | Not reported |
Published upstream
May 1, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: pstore: inode: Only d_invalidate() is needed Unloading a modular pstore backend with records in pstorefs would trigger the dput() double-drop warning: WARNING: CPU: 0 PID: 2569 at fs/dcache.c:762 dput.part.0+0x3f3/0x410 Using the combo of d_drop()/dput() (as mentioned in Documentation/filesystems/vfs.rst) isn't the right approach here, and leads to the reference counting problem seen above. Use d_invalidate() and update the code to not bother checking for error codes that can never happen. ---
Quoted source text, attributed separately from HOL analysis.