CVE-2024-39494: Debian Linux
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ima: Fix use-after-free on a dentry's dname.name ->d_name.name can change on rename and the earlier value can be freed; there are conditions sufficient to stabilize it (->d_lock on dentry, ->d_lock on its parent, ->i_rwsem exclusive on the parent's inode, rename_lock), but none of those are met at any of the sites. Take a stable snapshot of the name instead.
Affected products
- Debian Debian Linux: version 11.0 only
- Linux Linux Kernel: from 3.19, before 5.4.291 (fixed in 5.4.291); from 5.5, before 5.10.235 (fixed in 5.10.235); from 5.11, before 5.15.174 (fixed in 5.15.174); from 5.16, before 6.1.97 (fixed in 6.1.97); from 6.2, before 6.6.35 (fixed in 6.6.35); from 6.7, before 6.9.6 (fixed in 6.9.6)
Published 2024-07-12. Last modified 2026-08-04.