CVE-2024-14027 is a local denial-of-service vulnerability in the Linux kernel fs/xattr subsystem. In the fremovexattr() syscall, the kernel acquires a file reference via fdget(), but on the error path where strncpy_from_user() fails while copying the extended-attribute name from user space, execution returns without a corresponding fdput(). In multi-threaded processes where fdget() takes the slow path, this causes a permanent file reference leak on each trigger. The leaked references pin the associated struct file and related kernel objects in memory, resulting in unbounded kernel memory consumption. The issue was inadvertently fixed upstream by commit a71874379ec8 ("xattr: switch to CLASS(fd)").
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains two standalone C local kernel exploits plus documentation: README.md, WRITEUP.md, exploit.c, and exploit_dc.c. The code targets CVE-2024-14027, a Linux kernel refcount leak in fremovexattr() that can be abused on 32-bit systems to overflow struct file->f_count, free the file object, and reclaim it with another struct file of the same slab type. exploit.c is a local file-disclosure exploit. It creates pipe/file allocations to shape the filp slab, opens a target file and duplicates its fd, uses clone(CLONE_FILES) so fdget() takes the slow path, and spawns worker threads that repeatedly invoke fremovexattr(fd, 0x1) via raw int 0x80 to leak references until 32-bit f_count wraps to zero. It then carefully orchestrates inherited fd closes across parent/children to free the struct file without further disruptive allocations. A spawner process repeatedly execs /usr/bin/passwd -S so a privileged open of /etc/shadow reclaims the freed slot. The parent monitors the stale dangling fd in sacrificial child processes using fcntl(F_GETFL) and fstat()/dev+inode matching; on success it reads and prints /etc/shadow. This is a real exploit, not just a detector. exploit_dc.c is a more advanced local privilege-escalation exploit using a double-close technique. It follows the same initial refcount-overflow/UAF pattern, then reallocates the freed struct file with temporary writable files, identifies the reclaimed object through the stale fd, and mmaps the matching temp file with MAP_SHARED/PROT_WRITE. After closing the temp fds and the dangling fd to free the struct file again, it sprays opens of a SUID binary (default /usr/bin/chfn) so the mmap's vm_file now points at the SUID file's struct file/address_space. A memcpy into the writable mapping then faults pages into the SUID binary's page cache, effectively overwriting the SUID executable with the exploit binary. The program then execs the overwritten SUID binary; when run with euid 0, it executes /bin/sh as root. The code also daemonizes afterward to avoid cleanup paths touching dangling references. Overall purpose: demonstrate practical exploitation of a Linux kernel same-type object reuse bug for both sensitive file disclosure and full root privilege escalation. The repository is small, focused, and operational, with the markdown files explaining the vulnerability and exploitation strategy and the two C files serving as the main exploit entry points.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as one of many CVEs addressed by SUSE kernel security updates; no vulnerability details are provided in the content.
Listed as one of 206 vulnerabilities addressed by a SUSE kernel security update; no per-CVE technical detail is provided in the content.
A Linux kernel local denial-of-service vulnerability in fs/xattr where fremovexattr() can leak file references on an error path, allowing an unprivileged local user to cause kernel memory exhaustion.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.