---
id: CVE-2024-14027
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fs/xattr: missing fdput() in fremovexattr error path

  In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a
  file reference but returns early withou…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fs/xattr: missing fdput() in fremovexattr error path

  In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a
  file reference but returns early withou…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-401
published: '2026-03-09'
updated: '2026-06-26'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-14027'
references:
  - url: 'https://git.kernel.org/stable/c/9a3a2ae5efbbcaed37551218abed94e23c537157'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a71874379ec8c6e788a61d71b3ad014a8d9a5c08'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d151b94967c8247005435b63fc60f8f4baa320da'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - exploit-available
epss: 0.0021
epssPercentile: 0.09956
ingestedAt: '2026-06-29T13:24:34.791Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/lcfr-eth/CVE-2024-14027_slop'
  checkedAt: '2026-09-25T08:20:47.388Z'
exploitAvailable: true
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

fs/xattr: missing fdput() in fremovexattr error path

In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a
file reference but returns early without calling fdput() when
strncpy_from_user() fails on the name argument. In multi-threaded processes
where fdget() takes the slow path, this permanently leaks one
file reference per call, pinning the struct file and associated kernel
objects in memory. An unprivileged local user can exploit this to cause
kernel memory exhaustion. The issue was inadvertently fixed by commit
a71874379ec8 ("xattr: switch to CLASS(fd)").

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
