CVE-2024-40938: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: landlock: Fix d_parent walk The WARN_ON_ONCE() in collect_domain_accesses() can be triggered when trying to link a root mount point. This cannot work in practice because this directory is mounted, but the VFS check is done after the call to security_path_link(). Do not use source directory's d_parent when the source directory is the mount point. [mic: Fix commit message]

Affected products

  • Linux Linux Kernel: from 5.19, before 6.1.95 (fixed in 6.1.95); from 6.2, before 6.6.35 (fixed in 6.6.35); from 6.7, before 6.9.6 (fixed in 6.9.6); version 6.10 only

Published 2024-07-12. Last modified 2026-06-17.