CVE-2024-14027General(linux / linux_kernel)

MEDIUMCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error path In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a file reference but returns early without calling fdput() when strncpy_from_user() fails on the name argument. In multi-threaded processes where fdget() takes the slow path, this permanently leaks one file reference per call, pinning the struct file and associated kernel objects in memory. An unprivileged local user can exploit this to cause kernel memory exhaustion. The issue was inadvertently fixed by commit a71874379ec8 ("xattr: switch to CLASS(fd)").

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-09); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
linux_kernel

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-09: 3Mentions · 2026-03-13: 1Mentions · 2026-03-16: 1Mentions · 2026-06-02: 1PoC Mentioned / Linked · 2026-03-13: 1Exploit Tool / Code · 2026-03-13: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-06-02: 1Technical Details · 2026-03-09: 2Technical Details · 2026-03-16: 103-0903-1303-1606-02
Signal classification4 categories
General
233.3%
Patch
233.3%
Disclosure
116.7%
PoC
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-093
Disclosure1General1Patch1
2026-03-131
PoC1
2026-03-161
General1
2026-06-021
Patch1
Full discourse6 posts
  • LCFR@lcfr_eth
    PoC

    Here's the slopsploits for CVE-2024-14027 that were produced in roughly 2-3x the amount of time a human would have done it. As well as some thoughts/notes. https://github.com/lcfr-eth/CVE-2024-14027_slop/

    Post summary

    The post shares a GitHub repository containing a PoC/slop exploit for CVE‑2024‑14027, indicating automated generation of exploit code.

    261352921.6K
    2.5K followersView on X
  • Brad Spengler@spendergrsec
    General

    A CVE with actual text not provided by the commit description (since it was an Al Viro commit with no commit message): https://lore.kernel.org/linux-cve-announce/2026030917-CVE-2024-14027-5c00@gregkh/T/#u

    Post summary

    The note merely indicates a CVE was reported in the kernel commit, but provides no details, PoC, exploitation evidence, or patch information.

    1001112.0K
    4.4K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2024-14027 In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error path In the Linux kernel, the fremovexattr() sys… https://www.cve.org/CVERecord?id=CVE-2024-14027

    Post summary

    CVE-2024-14027, affecting the Linux kernel’s fremovexattr handling, has been fixed—patching the missing fdput() in the error path.

    00001108
    56.6K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: SUSE Linux Enterprise 16.0 ships kernel updates fixing 206 security issues, including CVE-2023-2058, CVE-2024-14027 and KVM, NVMe bugs rated important. https://threatcluster.io/cluster/suse-linux-kernel-updates-address-multiple-security-vulnerab-3131b205

    Post summary

    SUSE Linux Enterprise 16.0 releases kernel updates that address 206 security issues, including CVE-2023-2058 and CVE-2024-14027, thereby providing official patches for these vulnerabilities.

    0000064
    294 followersView on X
  • VulnTracker@vuln_tracker
    General

    @Dinosn Claude Opus tackling kernel vulnerabilities like CVE-2024-14027 shows how much LLMs understand about memory corruption. https://vulntracker.io/cves/CVE-2024-14027

    Post summary

    The tweet notes that Claude Opus is addressing kernel memory‑corruption vulnerabilities like CVE‑2024‑14027, illustrating what LLMs can comprehend about such issues.

    0000085
    424 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2024-14027 Linux Kernel Memory Leak via Unfreed File Reference in fremovexattr() Syscall https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-14027

    Post summary

    This post announces the CVE‑2024‑14027 vulnerability, detailing a memory‑leak in the Linux kernel’s fremovexattr() syscall, with no evidence of exploits, patches, or active exploitation.

    0000055
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---

Explore more