CVE-2026-53050

Local kernel memory corruption via quota race

Published Jun 24, 2026 · Updated Jun 24, 2026

Race condition in Linux Kernel allows local users to access a freed quota object by racing quota scanning with quota deactivation. dquot_scan_active() increments dq_count for an active dquot that quota_release_workfn() has already moved to the releasing list, leaving both paths able to operate on the same object. The path requires local low-privileged access, quota activity on a mounted OCFS2 filesystem, and memory pressure; the documented consequence is a use-after-free.

CVSS severity7.8
High
EPSS probability0.10%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Race condition in Linux Kernel allows local users to access a freed quota object by racing quota scanning with quota deactivation. dquot_scan_active() increments dq_count for an active dquot that quota_release_workfn() has already moved to the releasing list, leaving both paths able to operate on the same object. The path requires local low-privileged access, quota activity on a mounted OCFS2 filesystem, and memory pressure; the documented consequence is a use-after-free.

The record

CVE
CVE-2026-53050
Published
Jun 24, 2026
Updated
Jun 24, 2026
Vendor
The Linux Kernel Organization
Product
Linux Kernel
Classifications
CWE-362, T1499.004
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Jun 24, 2026CVE publishedPublication date reported by the CVE source.
  2. Jun 24, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=061a18239ced5eb086967a2b4451cb1cc5ce0702
  2. Affected versionversion=12a820a9923c11e8e898da9f82c8aded70cdcd16 <ac8a2e0d287ebf35e5d7e51e260b4e146648ba4a
  3. Affected versionversion=22c06bf1f99ec3ec16b1a81342becba4c59a1f16 <2bdc80f4619411e5bd4a3ef23f51e14021ed457c
  4. Affected versionversion=2a1ddddba6541143c8f73962f3021f1789114284
  5. Affected versionversion=4.19.297 <4.20
  6. Affected versionversion=5.10.199 <5.10.258
  7. Affected versionversion=5.15.136 <5.15.209
  8. Affected versionversion=5.4.259 <5.5
  9. Affected versionversion=56e96b38d2f7cd95b3c30eb70decac7233915e0a <f9438cb8c8ec3adc84b2b450a3aab0123d074c3b
  10. Affected versionversion=6.1.59 <6.1.175
  11. Affected versionversion=6.5.8 <6.6
  12. Affected versionversion=6.6
  13. Affected versionversion=869b6ea1609f655a43251bf41757aa44e5350a8f <61e25f664dc2a08299e07d84c85776abc2350f75
  14. Affected versionversion=869b6ea1609f655a43251bf41757aa44e5350a8f <6678dde265708003c2b42551af4a2e3cb05decd5
  15. Affected versionversion=869b6ea1609f655a43251bf41757aa44e5350a8f <82cbdb4c1ebb5ea7d7bd45c18d3483b5bd32ebc1
  16. Affected versionversion=869b6ea1609f655a43251bf41757aa44e5350a8f <e93ab401da4b2e2c1b8ef2424de2f238d51c8b2d
  17. Affected versionversion=869b6ea1609f655a43251bf41757aa44e5350a8f <fdd424d7c35633ac577fd87d1b043d1b8a6cd350
  18. Affected versionversion=bb7e3a019b52d829949d02b64ebab37838148fbf

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linux Kernelversion=061a18239ced5eb086967a2b4451cb1cc5ce0702; version=12a820a9923c11e8e898da9f82c8aded70cdcd16 <ac8a2e0d287ebf35e5d7e51e260b4e146648ba4a; version=22c06bf1f99ec3ec16b1a81342becba4c59a1f16 <2bdc80f4619411e5bd4a3ef23f51e14021ed457c; version=2a1ddddba6541143c8f73962f3021f1789114284; version=4.19.297 <4.20; version=5.10.199 <5.10.258; version=5.15.136 <5.15.209; version=5.4.259 <5.5; version=56e96b38d2f7cd95b3c30eb70decac7233915e0a <f9438cb8c8ec3adc84b2b450a3aab0123d074c3b; version=6.1.59 <6.1.175; version=6.5.8 <6.6; version=6.6; version=869b6ea1609f655a43251bf41757aa44e5350a8f <61e25f664dc2a08299e07d84c85776abc2350f75; version=869b6ea1609f655a43251bf41757aa44e5350a8f <6678dde265708003c2b42551af4a2e3cb05decd5; version=869b6ea1609f655a43251bf41757aa44e5350a8f <82cbdb4c1ebb5ea7d7bd45c18d3483b5bd32ebc1; version=869b6ea1609f655a43251bf41757aa44e5350a8f <e93ab401da4b2e2c1b8ef2424de2f238d51c8b2d; version=869b6ea1609f655a43251bf41757aa44e5350a8f <fdd424d7c35633ac577fd87d1b043d1b8a6cd350; version=bb7e3a019b52d829949d02b64ebab37838148fbf

Published CVSS scores

7.8kernel.orgCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
T1499.004Application or System Exploitation

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo