CVE-2024-53685

MEDIUM EPSS 12.1%
Published Jan 11, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Jan 11, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ceph: give up on paths longer than PATH_MAX If the full path to be built by ceph_mdsc_build_path() happens to be longer than PATH_MAX, then this function will enter an endless (retry) loop, effectively blocking the whole task. Most of the machine becomes unusable, making this a very simple and effective DoS vulnerability. I cannot imagine why this retry was ever implemented, but it seems rather useless and harmful to me. Let's remove it and fail with ENAMETOOLONG instead.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
12.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-835

Affected Products 15

VendorProductVersionRange
linuxlinux_kernel*≥2.6.35  –  <5.10.234
linuxlinux_kernel*≥5.11  –  <5.15.177
linuxlinux_kernel*≥5.16  –  <6.1.125
linuxlinux_kernel*≥6.2  –  <6.6.70
linuxlinux_kernel*≥6.7  –  <6.12.7
linuxlinux_kernel2.6.34any
linuxlinux_kernel2.6.34any
linuxlinux_kernel2.6.34any
linuxlinux_kernel2.6.34any
linuxlinux_kernel2.6.34any
linuxlinux_kernel2.6.34any
linuxlinux_kernel2.6.34any
linuxlinux_kernel6.13any
linuxlinux_kernel6.13any
linuxlinux_kernel6.13any

References 8

  • git.kernel.org https://git.kernel.org/stable/c/0f2b2d9e881c90402dbe28f9ba831775b7992e1f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/550f7ca98ee028a606aa75705a7e77b1bd11720f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/99a37ab76a315c8307eb5b0dc095d8ad9d8efeaa
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c47ed91156daf328601d02b58d52d9804da54108
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d42ad3f161a5a487f81915c406f46943c7187a0a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e4b168c64da06954be5d520f6c16469b1cadc069
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/0f2b2d9e881c90402dbe28f9ba831775b7992e1f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/550f7ca98ee028a606aa75705a7e77b1bd11720f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/99a37ab76a315c8307eb5b0dc095d8ad9d8efeaa
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c47ed91156daf328601d02b58d52d9804da54108
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d42ad3f161a5a487f81915c406f46943c7187a0a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e4b168c64da06954be5d520f6c16469b1cadc069
    Patch