CVE-2024-56780 - CVE House
Back to Database
Status published Unknown CVE-2024-56780

quota: flush quota_release_work upon quota writeback

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: quota: flush quota_release_work upon quota writeback One of the paths quota writeback is called from is: freeze_super() sync_filesystem() ext4_sync_fs() dquot_writeback_dquots() Since we currently don't always flush the quota_release_work queue in this path, we can end up with the following race: 1. dquot are added to releasing_dquots list during regular operations. 2. FS Freeze starts, however, this does not flush the quota_release_work queue. 3. Freeze completes. 4. Kernel eventually tries to flush the workqueue while FS is frozen which hits a WARN_ON since transaction gets started during frozen state: ext4_journal_check_start+0x28/0x110 [ext4] (unreliable) __ext4_journal_start_sb+0x64/0x1c0 [ext4] ext4_release_dquot+0x90/0x1d0 [ext4] quota_release_workfn+0x43c/0x4d0 Which is the following line: WARN_ON(sb->s_writers.frozen == SB_FREEZE_COMPLETE); Which ultimately results in generic/390 failing due to dmesg noise. This was detected on powerpc machine 15 cores. To avoid this, make sure to flush the workqueue during dquot_writeback_dquots() so we dont have any pending workitems after freeze.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-56780

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
d40c192e119892799dd4ddf94f5cea6fa93775ef, 86d89987f0998c98f57d641e308b40452a994045, 89602de9a2d7080b7a4029d5c1bf8f78d295ff5f, 3027e200dd58d5b437f16634dbbd355b29ffe0a6, dabc8b20756601b9e1cc85a81d47d3f98ed4d13a, f3e9a2bbdeb8987508dd6bb2b701dea911d4daec, 903fc5d8cb48b0d2de7095ef40e39fd32bb27bd0, 31bed65eecbc5ce57592cfe31947eaa64e3d678e, 5.4.257, 5.10.195, 5.15.132, 6.1.53, 4.19.295, 6.4.16, 6.5.3, 6.6, 0, 5.4.287, 5.10.231, 5.15.174, 6.1.120, 6.6.64, 6.12.4, 6.13

Timeline

Official Publish: January 8th, 2025
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.