CVE-2024-58088 is a Linux kernel BPF flaw that lets a sufficiently privileged local attacker cause a system deadlock while cgroup local storage is being freed. Introduced in kernel 6.2, the affected BPF_MAP_TYPE_CGRP_STORAGE cleanup path passed a null busy counter to bpf_local_storage_map_free(), enabling a BPF program invoked during cleanup to recursively access storage and attempt to reacquire an already held local-storage lock. Repeated creation and destruction of crafted BPF programs can leave a worker thread deadlocked, causing an availability impact.
The issue is fixed upstream in Linux 6.6.80, 6.12.17, 6.13.5, and 6.14-rc4 and later; administrators should deploy a current stable kernel rather than cherry-pick the patch. Red Hat rates the issue Moderate (CVSS 4.4) and has issued fixes for RHEL 9 and RHEL 10 through RHSA-2025:20518 and RHSA-2025:20095; RHEL 9 kernel-rt is affected, while RHEL 6, 7, 8 and their listed real-time kernel variants lack the vulnerable code.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:20095 for RHEL 10 and RHSA-2025:20518 for the standard RHEL 9 kernel, addressing CVE-2024-58088. RHEL 9 kernel-rt remained listed as affected without an identified erratum.
The remediation passes the cgroup-storage busy counter to the map-free procedure before storage and map locking. Fixes were included in Linux kernel versions 6.6.80, 6.12.17, 6.13.5, and 6.14-rc4.
The Linux kernel CVE team assigned CVE-2024-58088 to the BPF cgroup-storage cleanup deadlock issue. The flaw can be triggered by BPF programs that recursively access cgroup storage while local-storage locking is in progress.
Linux kernel 6.2 introduced cgroup storage for non-cgroup-attached BPF programs through commit c4bcfb38a95e. Its cgroup-storage cleanup path passed a NULL busy counter to bpf_local_storage_map_free(), creating a locking window that could lead to deadlock.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.