CVE-2026-53050
In the Linux kernel, the following vulnerability has been resolved:
quota: Fix race of dquot_scan_active() with quota deactivation
dquot_scan_active() can race with quota deactivation in quota_release_workfn() like:
The problem is not only a cosmetic one as under memory pressure the caller of dquot_scan_active() can end up working on freed dquot.
Fix the problem by making sure the dquot is removed from releasing list when we acquire a reference to it.
Detalles técnicos trazas, registros y código del informe original
CPU0 (quota_release_workfn) CPU1 (dquot_scan_active)
============================== ==============================
spin_lock(&dq_list_lock);
list_replace_init(
&releasing_dquots, &rls_head);
/* dquot X on rls_head,
dq_count == 0,
DQ_ACTIVE_B still set */
spin_unlock(&dq_list_lock);
synchronize_srcu(&dquot_srcu);
spin_lock(&dq_list_lock);
list_for_each_entry(dquot,
&inuse_list, dq_inuse) {
/* finds dquot X */
dquot_active(X) -> true
atomic_inc(&X->dq_count);
}
spin_unlock(&dq_list_lock);
spin_lock(&dq_list_lock);
dquot = list_first_entry(&rls_head);
WARN_ON_ONCE(atomic_read(&dquot->dq_count));CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.14%
- Percentil entre todas las CVEs puntuadas: 3
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 %
Vulnerabilidad de escalada de privilegios en el kernel de Linux (acceso local, PR:L, sin interacción de usuario). La condición de carrera permite corrupción de memoria que el atacante local puede explotar para elevar privilegios o ejecutar código con permisos elevados.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-362
Referencias
- https://git.kernel.org/stable/c/2bdc80f4619411e5bd4a3ef23f51e14021ed457c
- https://git.kernel.org/stable/c/61e25f664dc2a08299e07d84c85776abc2350f75
- https://git.kernel.org/stable/c/6678dde265708003c2b42551af4a2e3cb05decd5
- https://git.kernel.org/stable/c/82cbdb4c1ebb5ea7d7bd45c18d3483b5bd32ebc1
- https://git.kernel.org/stable/c/ac8a2e0d287ebf35e5d7e51e260b4e146648ba4a
- https://git.kernel.org/stable/c/e93ab401da4b2e2c1b8ef2424de2f238d51c8b2d
- https://git.kernel.org/stable/c/f9438cb8c8ec3adc84b2b450a3aab0123d074c3b
- https://git.kernel.org/stable/c/fdd424d7c35633ac577fd87d1b043d1b8a6cd350
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-53050",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "22c06bf1f99ec3ec16b1a81342becba4c59a1f16",
"lessThan": "2bdc80f4619411e5bd4a3ef23f51e14021ed457c",
"versionType": "git"
},
{
"status": "affected",
"version": "56e96b38d2f7cd95b3c30eb70decac7233915e0a",
"lessThan": "f9438cb8c8ec3adc84b2b450a3aab0123d074c3b",
"versionType": "git"
},
{
"status": "affected",
"version": "12a820a9923c11e8e898da9f82c8aded70cdcd16",
"lessThan": "ac8a2e0d287ebf35e5d7e51e260b4e146648ba4a",
"versionType": "git"
},
{
"status": "affected",
"version": "869b6ea1609f655a43251bf41757aa44e5350a8f",
"lessThan": "6678dde265708003c2b42551af4a2e3cb05decd5",
"versionType": "git"
},
{
"status": "affected",
"version": "869b6ea1609f655a43251bf41757aa44e5350a8f",
"lessThan": "61e25f664dc2a08299e07d84c85776abc2350f75",
"versionType": "git"
},
{
"status": "affected",
"version": "869b6ea1609f655a43251bf41757aa44e5350a8f",
"lessThan": "fdd424d7c35633ac577fd87d1b043d1b8a6cd350",
"versionType": "git"
},
{
"status": "affected",
"version": "869b6ea1609f655a43251bf41757aa44e5350a8f",
"lessThan": "82cbdb4c1ebb5ea7d7bd45c18d3483b5bd32ebc1",
"versionType": "git"
},
{
"status": "affected",
"version": "869b6ea1609f655a43251bf41757aa44e5350a8f",
"lessThan": "e93ab401da4b2e2c1b8ef2424de2f238d51c8b2d",
"versionType": "git"
},
{
"status": "affected",
"version": "bb7e3a019b52d829949d02b64ebab37838148fbf",
"versionType": "git"
},
{
"status": "affected",
"version": "061a18239ced5eb086967a2b4451cb1cc5ce0702",
"versionType": "git"
},
{
"status": "affected",
"version": "2a1ddddba6541143c8f73962f3021f1789114284",
"versionType": "git"
},
{
"status": "affected",
"version": "5.10.199",
"lessThan": "5.10.258",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.15.136",
"lessThan": "5.15.209",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.59",
"lessThan": "6.1.175",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.19.297",
"lessThan": "4.20",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.4.259",
"lessThan": "5.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.5.8",
"lessThan": "6.6",
"versionType": "semver"
}
],
"programFiles": [
"fs/quota/dquot.c",
"include/linux/quotaops.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.6",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/quota/dquot.c",
"include/linux/quotaops.h"
],
"defaultStatus": "affected"
}
]
},
{
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"affectedData": [
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-06-24T17:17:16.887",
"references": [
{
"url": "https://git.kernel.org/stable/c/2bdc80f4619411e5bd4a3ef23f51e14021ed457c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/61e25f664dc2a08299e07d84c85776abc2350f75",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6678dde265708003c2b42551af4a2e3cb05decd5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/82cbdb4c1ebb5ea7d7bd45c18d3483b5bd32ebc1",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ac8a2e0d287ebf35e5d7e51e260b4e146648ba4a",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e93ab401da4b2e2c1b8ef2424de2f238d51c8b2d",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f9438cb8c8ec3adc84b2b450a3aab0123d074c3b",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fdd424d7c35633ac577fd87d1b043d1b8a6cd350",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-362"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nquota: Fix race of dquot_scan_active() with quota deactivation\n\ndquot_scan_active() can race with quota deactivation in\nquota_release_workfn() like:\n\n CPU0 (quota_release_workfn) CPU1 (dquot_scan_active)\n ============================== ==============================\n spin_lock(&dq_list_lock);\n list_replace_init(\n &releasing_dquots, &rls_head);\n /* dquot X on rls_head,\n dq_count == 0,\n DQ_ACTIVE_B still set */\n spin_unlock(&dq_list_lock);\n synchronize_srcu(&dquot_srcu);\n spin_lock(&dq_list_lock);\n list_for_each_entry(dquot,\n &inuse_list, dq_inuse) {\n /* finds dquot X */\n dquot_active(X) -> true\n atomic_inc(&X->dq_count);\n }\n spin_unlock(&dq_list_lock);\n spin_lock(&dq_list_lock);\n dquot = list_first_entry(&rls_head);\n WARN_ON_ONCE(atomic_read(&dquot->dq_count));\n\nThe problem is not only a cosmetic one as under memory pressure the\ncaller of dquot_scan_active() can end up working on freed dquot.\n\nFix the problem by making sure the dquot is removed from releasing list\nwhen we acquire a reference to it."
}
],
"lastModified": "2026-09-08T09:18:14.037",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12E3A697-0D43-49C1-A30B-0365A1D27EFF",
"versionEndExcluding": "4.20",
"versionStartIncluding": "4.19.297"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8291EEE5-FECA-46F7-80D3-9C98F05C8995",
"versionEndExcluding": "5.5",
"versionStartIncluding": "5.4.259"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C0F45DF0-D7FD-4059-89F5-2D9D6CB1F245",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "5.10.199"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E79E1FFF-6B98-40D6-BD55-9157D9D56B99",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.15.136"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC7D346F-F289-4452-97CF-B5ACD4EEA193",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "6.1.59"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB6FAAAD-2171-4941-8EE2-DE548E9A1DD9",
"versionEndExcluding": "6.6",
"versionStartIncluding": "6.5.8"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0744696C-7355-4177-9EEE-693238BA5C21",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "6.6.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C918746B-DE6F-448F-A93E-A04C5481688D",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "96D99E49-380D-43AB-BDBA-25C3AD018A9C",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A13475D2-59BF-4716-94B5-7C1D239A2CF4",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.6:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E346B162-D566-4E62-ABDE-ECBFB21B8BFD"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.6:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E114E9DD-F7E1-40CC-AAD5-F14E586CB2E6"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.6:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC5BD782-474C-4A68-AED7-6EC818FF89AE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}