Review reviewHigh

CVE-2026-53050

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: quota: Fix race of dquot_scan_active() with quota deactivation dquot_scan_active() can race with quota deactivation in quota_release_workfn() like: CPU0 (quota_release_workfn) CPU1 (dquot_scan_active) ============================== ============================== spin_lock(&dq_list_lock); list_replace_init( &releasing_dquots, &rls_head); /* dquot X on rls_head, dq_count == 0, DQ_ACTIVE_B still set */ spin_unlock(&dq_list_lock); synchronize_srcu(&dquot_srcu); spin_lock(&dq_list_lock); list_for_each_entry(dquot, &inuse_list, d...

CVSS
7.8
EPSS
0.10%
0.99% percentile
CISA KEV
Not listed
Published
2026.06.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.10%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: quota: Fix race of dquot_scan_active() with quota deactivation dquot_scan_active() can race with quota deactivation in quota_release_workfn() like: CPU0 (quota_release_workfn) CPU1 (dquot_scan_active) ============================== ============================== spin_lock(&dq_list_lock); list_replace_init( &releasing_dquots, &rls_head); /* dquot X on rls_head, dq_count == 0, DQ_ACTIVE_B still set */ spin_unlock(&dq_list_lock); synchronize_srcu(&dquot_srcu); spin_lock(&dq_list_lock); list_for_each_entry(dquot, &inuse_list, d...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 22c06bf1f99ec3ec16b1a81342becba4c59a1f16 < 2bdc80f4619411e5bd4a3ef23f51e14021ed457c, >= 56e96b38d2f7cd95b3c30eb70decac7233915e0a < f9438cb8c8ec3adc84b2b450a3aab0123d074c3b, >= 12a820a9923c11e8e898da9f82c8aded70cdcd16 < ac8a2e0d287ebf35e5d7e51e260b4e146648ba4a, >= 869b6ea1609f655a43251bf41757aa44e5350a8f < 6678dde265708003c2b42551af4a2e3cb05decd5, >= 869b6ea1609f655a43251bf41757aa44e5350a8f < 61e25f664dc2a08299e07d84c85776abc2350f75, >= 869b6ea1609f655a43251bf41757aa44e5350a8f < fdd424d7c35633ac577fd87d1b043d1b8a6cd350, >= 869b6ea1609f655a43251bf41757aa44e5350a8f < 82cbdb4c1ebb5ea7d7bd45c18d3483b5bd32ebc1, >= 869b6ea1609f655a43251bf41757aa44e5350a8f < e93ab401da4b2e2c1b8ef2424de2f238d51c8b2d, >= bb7e3a019b52d829949d02b64ebab37838148fbf, >= 061a18239ced5eb086967a2b4451cb1cc5ce0702, >= 2a1ddddba6541143c8f73962f3021f1789114284, >= 5.10.199 < 5.10.258, >= 5.15.136 < 5.15.209, >= 6.1.59 < 6.1.175, >= 4.19.297 < 4.20, >= 5.4.259 < 5.5, >= 6.5.8 < 6.6, >= 6.6, >= 6.6.1 < 6.6.141, >= 6.7 < 6.12.91
Fixed versions
4.20, 5.5, 5.10.258, 5.15.209, 6.1.175, 6.6, 6.6.141, 6.12.91, 6.18.33, 7.0.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-362
CVE-2026-53050 — Linux Linux, linux kernel | SECUFOCUS NOW