Search

Find a vulnerability

Search criteria

    169 vulnerabilities found for linux_kernel by linux

    CVE-2024-50066 (GCVE-0-2024-50066)

    Vulnerability from cvelistv5 – Published: 2024-10-23 05:20 – Updated: 2026-08-05 11:41
    VLAI
    Title
    mm/mremap: fix move_normal_pmd/retract_page_tables race
    Summary
    In the Linux kernel, the following vulnerability has been resolved: mm/mremap: fix move_normal_pmd/retract_page_tables race In mremap(), move_page_tables() looks at the type of the PMD entry and the specified address range to figure out by which method the next chunk of page table entries should be moved. At that point, the mmap_lock is held in write mode, but no rmap locks are held yet. For PMD entries that point to page tables and are fully covered by the source address range, move_pgt_entry(NORMAL_PMD, ...) is called, which first takes rmap locks, then does move_normal_pmd(). move_normal_pmd() takes the necessary page table locks at source and destination, then moves an entire page table from the source to the destination. The problem is: The rmap locks, which protect against concurrent page table removal by retract_page_tables() in the THP code, are only taken after the PMD entry has been read and it has been decided how to move it. So we can race as follows (with two processes that have mappings of the same tmpfs file that is stored on a tmpfs mount with huge=advise); note that process A accesses page tables through the MM while process B does it through the file rmap: process A process B ========= ========= mremap mremap_to move_vma move_page_tables get_old_pmd alloc_new_pmd *** PREEMPT *** madvise(MADV_COLLAPSE) do_madvise madvise_walk_vmas madvise_vma_behavior madvise_collapse hpage_collapse_scan_file collapse_file retract_page_tables i_mmap_lock_read(mapping) pmdp_collapse_flush i_mmap_unlock_read(mapping) move_pgt_entry(NORMAL_PMD, ...) take_rmap_locks move_normal_pmd drop_rmap_locks When this happens, move_normal_pmd() can end up creating bogus PMD entries in the line `pmd_populate(mm, new_pmd, pmd_pgtable(pmd))`. The effect depends on arch-specific and machine-specific details; on x86, you can end up with physical page 0 mapped as a page table, which is likely exploitable for user->kernel privilege escalation. Fix the race by letting process B recheck that the PMD still points to a page table after the rmap locks have been taken. Otherwise, we bail and let the caller fall back to the PTE-level copying path, which will then bail immediately at the pmd_none() check. Bug reachability: Reaching this bug requires that you can create shmem/file THP mappings - anonymous THP uses different code that doesn't zap stuff under rmap locks. File THP is gated on an experimental config flag (CONFIG_READ_ONLY_THP_FOR_FS), so on normal distro kernels you need shmem THP to hit this bug. As far as I know, getting shmem THP normally requires that you can mount your own tmpfs with the right mount flags, which would require creating your own user+mount namespace; though I don't know if some distros maybe enable shmem THP by default or something like that. Bug impact: This issue can likely be used for user->kernel privilege escalation when it is reachable.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-23 04:55 UTC
    CWE
    • CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 1d65b771bc08cd054cf6d3766a72e113dc46d62f , < 17396e32f975130b3e6251f024c8807d192e4c3e (git)
    Affected: 1d65b771bc08cd054cf6d3766a72e113dc46d62f , < 1552ce9ce8af47c0fe911682e5e1855e25851ca9 (git)
    Affected: 1d65b771bc08cd054cf6d3766a72e113dc46d62f , < 6fa1066fc5d00cb9f1b0e83b7ff6ef98d26ba2aa (git)
    Create a notification for this product.
    Linux Linux Affected: 6.6
    Unaffected: 0 , < 6.6 (semver)
    Unaffected: 6.6.58 , ≤ 6.6.* (semver)
    Unaffected: 6.11.5 , ≤ 6.11.* (semver)
    Unaffected: 6.12 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 6.6 , < 6.6.58 (custom)
    Unaffected: 6.6.58 , < 6.7 (custom)
    Unaffected: 6.11.5 , < 6.12 (custom)
    Unaffected: 6.12 , < * (custom)
    Affected: 1d65b771bc08 , < 17396e32f975 (git)
    Affected: 1d65b771bc08 , < 1552ce9ce8af (git)
    Affected: 1d65b771bc08 , < 6fa1066fc5d0 (git)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.6.58",
                    "status": "affected",
                    "version": "6.6",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "6.7",
                    "status": "unaffected",
                    "version": "6.6.58",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "6.12",
                    "status": "unaffected",
                    "version": "6.11.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "6.12",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "17396e32f975",
                    "status": "affected",
                    "version": "1d65b771bc08",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "1552ce9ce8af",
                    "status": "affected",
                    "version": "1d65b771bc08",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "6fa1066fc5d0",
                    "status": "affected",
                    "version": "1d65b771bc08",
                    "versionType": "git"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-50066",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-23T04:55:50.463779Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-362",
                    "description": "CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-25T14:12:03.999Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-03-07T16:19:11.266Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.vicarius.io/vsociety/posts/cve-2024-50066-kernel-mitigation-vulnerability"
              },
              {
                "url": "https://www.vicarius.io/vsociety/posts/cve-2024-50066-kernel-detection-vulnerability"
              }
            ],
            "title": "CVE Program Container",
            "x_generator": {
              "engine": "ADPogram 0.0.1"
            }
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "mm/mremap.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "17396e32f975130b3e6251f024c8807d192e4c3e",
                  "status": "affected",
                  "version": "1d65b771bc08cd054cf6d3766a72e113dc46d62f",
                  "versionType": "git"
                },
                {
                  "lessThan": "1552ce9ce8af47c0fe911682e5e1855e25851ca9",
                  "status": "affected",
                  "version": "1d65b771bc08cd054cf6d3766a72e113dc46d62f",
                  "versionType": "git"
                },
                {
                  "lessThan": "6fa1066fc5d00cb9f1b0e83b7ff6ef98d26ba2aa",
                  "status": "affected",
                  "version": "1d65b771bc08cd054cf6d3766a72e113dc46d62f",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "mm/mremap.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.6"
                },
                {
                  "lessThan": "6.6",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.58",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.11.*",
                  "status": "unaffected",
                  "version": "6.11.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.12",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.58",
                      "versionStartIncluding": "6.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.11.5",
                      "versionStartIncluding": "6.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12",
                      "versionStartIncluding": "6.6",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mremap: fix move_normal_pmd/retract_page_tables race\n\nIn mremap(), move_page_tables() looks at the type of the PMD entry and the\nspecified address range to figure out by which method the next chunk of\npage table entries should be moved.\n\nAt that point, the mmap_lock is held in write mode, but no rmap locks are\nheld yet.  For PMD entries that point to page tables and are fully covered\nby the source address range, move_pgt_entry(NORMAL_PMD, ...) is called,\nwhich first takes rmap locks, then does move_normal_pmd(). \nmove_normal_pmd() takes the necessary page table locks at source and\ndestination, then moves an entire page table from the source to the\ndestination.\n\nThe problem is: The rmap locks, which protect against concurrent page\ntable removal by retract_page_tables() in the THP code, are only taken\nafter the PMD entry has been read and it has been decided how to move it. \nSo we can race as follows (with two processes that have mappings of the\nsame tmpfs file that is stored on a tmpfs mount with huge=advise); note\nthat process A accesses page tables through the MM while process B does it\nthrough the file rmap:\n\nprocess A                      process B\n=========                      =========\nmremap\n  mremap_to\n    move_vma\n      move_page_tables\n        get_old_pmd\n        alloc_new_pmd\n                      *** PREEMPT ***\n                               madvise(MADV_COLLAPSE)\n                                 do_madvise\n                                   madvise_walk_vmas\n                                     madvise_vma_behavior\n                                       madvise_collapse\n                                         hpage_collapse_scan_file\n                                           collapse_file\n                                             retract_page_tables\n                                               i_mmap_lock_read(mapping)\n                                               pmdp_collapse_flush\n                                               i_mmap_unlock_read(mapping)\n        move_pgt_entry(NORMAL_PMD, ...)\n          take_rmap_locks\n          move_normal_pmd\n          drop_rmap_locks\n\nWhen this happens, move_normal_pmd() can end up creating bogus PMD entries\nin the line `pmd_populate(mm, new_pmd, pmd_pgtable(pmd))`.  The effect\ndepends on arch-specific and machine-specific details; on x86, you can end\nup with physical page 0 mapped as a page table, which is likely\nexploitable for user-\u003ekernel privilege escalation.\n\nFix the race by letting process B recheck that the PMD still points to a\npage table after the rmap locks have been taken.  Otherwise, we bail and\nlet the caller fall back to the PTE-level copying path, which will then\nbail immediately at the pmd_none() check.\n\nBug reachability: Reaching this bug requires that you can create\nshmem/file THP mappings - anonymous THP uses different code that doesn\u0027t\nzap stuff under rmap locks.  File THP is gated on an experimental config\nflag (CONFIG_READ_ONLY_THP_FOR_FS), so on normal distro kernels you need\nshmem THP to hit this bug.  As far as I know, getting shmem THP normally\nrequires that you can mount your own tmpfs with the right mount flags,\nwhich would require creating your own user+mount namespace; though I don\u0027t\nknow if some distros maybe enable shmem THP by default or something like\nthat.\n\nBug impact: This issue can likely be used for user-\u003ekernel privilege\nescalation when it is reachable."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - Both halves of the race are driven by local syscalls \u2014 `mremap()` in one process and `madvise(MADV_COLLAPSE)` in another (or background khugepaged) \u2014 against a shared tmpfs mapping. No network or physical access is involved.\nAC:L - The attacker controls both sides of the race: it runs process A\u0027s `mremap()` and process B\u0027s `MADV_COLLAPSE` on the same tmpfs file, and the window sits around a documented preemption/allocation point between `alloc_new_pmd()` and `move_pgt_entry(NORMAL_PMD, ...)`, so it can be widened with CPU pinning/memory pressure and retried indefinitely. Setting up shmem THP is an attacker-performed runtime action (`mount -t tmpfs -o huge=advise` inside its own user+mount namespace), not a condition beyond its control.\nPR:L - An ordinary unprivileged local user suffices \u2014 `mremap()` and `madvise(MADV_COLLAPSE)` have no capability checks, and the tmpfs `huge=` option is explicitly ungated (only `noswap`/`quota` require init_user_ns + CAP_SYS_ADMIN), so the required shmem THP mount is obtainable via unprivileged user+mount namespaces, which are enabled by default on major distros.\nUI:N - The attacker spawns and drives both racing processes itself; no victim action, mount, or file access by another user is required.\nS:U - This is a standard local kernel privilege escalation \u2014 the corruption occurs in kernel page tables and the impact stays within the same security authority (the OS kernel), with no VM/IOMMU boundary crossed.\nC:H - Physical page 0 gets installed as a live user-accessible page table, so its arbitrary contents are interpreted as PTEs, mapping attacker-reachable physical memory into userspace and enabling disclosure of kernel memory and other processes\u0027 data.\nI:H - The bogus page table yields an arbitrary physical memory write primitive (PTEs derived from page 0 carry `_PAGE_RW|_PAGE_USER`), allowing overwrite of kernel data such as `cred` structures; the reporter states it is likely exploitable for user-\u003ekernel privilege escalation.\nA:H - Corrupting the page-table tree with PFN 0, hitting `VM_BUG_ON`, and later freeing physical page 0 into the buddy allocator reliably produces kernel oops/panic and system-wide memory corruption."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:41:21.487Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/17396e32f975130b3e6251f024c8807d192e4c3e"
            },
            {
              "url": "https://git.kernel.org/stable/c/1552ce9ce8af47c0fe911682e5e1855e25851ca9"
            },
            {
              "url": "https://git.kernel.org/stable/c/6fa1066fc5d00cb9f1b0e83b7ff6ef98d26ba2aa"
            },
            {
              "url": "https://project-zero.issues.chromium.org/issues/371047675"
            }
          ],
          "title": "mm/mremap: fix move_normal_pmd/retract_page_tables race",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-50066",
        "datePublished": "2024-10-23T05:20:37.942Z",
        "dateReserved": "2024-10-21T19:36:19.939Z",
        "dateUpdated": "2026-08-05T11:41:21.487Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-40902 (GCVE-0-2024-40902)

    Vulnerability from cvelistv5 – Published: 2024-07-12 12:20 – Updated: 2026-08-05 11:33
    VLAI
    Title
    jfs: xattr: fix buffer overflow for invalid xattr
    Summary
    In the Linux kernel, the following vulnerability has been resolved: jfs: xattr: fix buffer overflow for invalid xattr When an xattr size is not what is expected, it is printed out to the kernel log in hex format as a form of debugging. But when that xattr size is bigger than the expected size, printing it out can cause an access off the end of the buffer. Fix this all up by properly restricting the size of the debug hex dump in the kernel log.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-16 04:02 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < f0dedb5c511ed82cbaff4997a8decf2351ba549f (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < 1e84c9b1838152a87cf453270a5fa75c5037e83a (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < fc745f6e83cb650f9a5f2c864158e3a5ea76dad0 (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < 480e5bc21f2c42d90c2c16045d64d824dcdd5ec7 (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < 33aecc5799c93d3ee02f853cb94e201f9731f123 (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < 4598233d9748fe4db4e13b9f473588aa25e87d69 (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < b537cb2f4c4a1357479716a9c339c0bda03d873f (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < 7c55b78818cfb732680c4a72ab270cc2d2ee3d0f (git)
    Create a notification for this product.
    Linux Linux Affected: 2.6.12
    Unaffected: 0 , < 2.6.12 (semver)
    Unaffected: 4.19.317 , ≤ 4.19.* (semver)
    Unaffected: 5.4.279 , ≤ 5.4.* (semver)
    Unaffected: 5.10.221 , ≤ 5.10.* (semver)
    Unaffected: 5.15.162 , ≤ 5.15.* (semver)
    Unaffected: 6.1.95 , ≤ 6.1.* (semver)
    Unaffected: 6.6.35 , ≤ 6.6.* (semver)
    Unaffected: 6.9.6 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < f0dedb5c511e (git)
    Affected: 1da177e4c3f4 , < 1e84c9b18381 (git)
    Affected: 1da177e4c3f4 , < fc745f6e83cb (git)
    Affected: 1da177e4c3f4 , < 480e5bc21f2c (git)
    Affected: 1da177e4c3f4 , < 33aecc5799c9 (git)
    Affected: 1da177e4c3f4 , < 4598233d9748 (git)
    Affected: 1da177e4c3f4 , < b537cb2f4c4a (git)
    Affected: 1da177e4c3f4 , < 7c55b78818cf (git)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T21:57:30.293Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/f0dedb5c511ed82cbaff4997a8decf2351ba549f"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/1e84c9b1838152a87cf453270a5fa75c5037e83a"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/fc745f6e83cb650f9a5f2c864158e3a5ea76dad0"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/480e5bc21f2c42d90c2c16045d64d824dcdd5ec7"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/33aecc5799c93d3ee02f853cb94e201f9731f123"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/4598233d9748fe4db4e13b9f473588aa25e87d69"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/b537cb2f4c4a1357479716a9c339c0bda03d873f"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/7c55b78818cfb732680c4a72ab270cc2d2ee3d0f"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "f0dedb5c511e",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "1e84c9b18381",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "fc745f6e83cb",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "480e5bc21f2c",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "33aecc5799c9",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "4598233d9748",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b537cb2f4c4a",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "7c55b78818cf",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-40902",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-16T04:02:10.264268Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-121",
                    "description": "CWE-121 Stack-based Buffer Overflow",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-20T14:03:35.925Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "fs/jfs/xattr.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "f0dedb5c511ed82cbaff4997a8decf2351ba549f",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "1e84c9b1838152a87cf453270a5fa75c5037e83a",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "fc745f6e83cb650f9a5f2c864158e3a5ea76dad0",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "480e5bc21f2c42d90c2c16045d64d824dcdd5ec7",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "33aecc5799c93d3ee02f853cb94e201f9731f123",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "4598233d9748fe4db4e13b9f473588aa25e87d69",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "b537cb2f4c4a1357479716a9c339c0bda03d873f",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "7c55b78818cfb732680c4a72ab270cc2d2ee3d0f",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "fs/jfs/xattr.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.6.12"
                },
                {
                  "lessThan": "2.6.12",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "4.19.*",
                  "status": "unaffected",
                  "version": "4.19.317",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.279",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.221",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.162",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.95",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.35",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.19.317",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.279",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.221",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.162",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.95",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.35",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.6",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: xattr: fix buffer overflow for invalid xattr\n\nWhen an xattr size is not what is expected, it is printed out to the\nkernel log in hex format as a form of debugging.  But when that xattr\nsize is bigger than the expected size, printing it out can cause an\naccess off the end of the buffer.\n\nFix this all up by properly restricting the size of the debug hex dump\nin the kernel log."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - Triggering requires a locally attached/mounted crafted JFS image, and the OOB read is reached through ordinary local syscalls (getxattr/listxattr/stat) on files in that filesystem. No network or remote-peer data path exists into fs/jfs/xattr.c.\nAC:L - The attacker fully controls every input \u2014 the on-disk `di_ea.flag`, the 32-bit `di_ea.size`, and the 128 inline EA bytes \u2014 so setting `EALIST_SIZE(xattr) != ea_size` with a huge `ea_size` deterministically drives print_hex_dump past the buffer. No race, no memory-layout dependency, no non-default config (JFS xattr support is unconditional in fs/jfs).\nPR:L - Once the image is mounted, any unprivileged user can trigger it via getxattr/listxattr or merely a permission check through jfs_get_acl, and the only CAP_SYS_ADMIN check on the path (can_list) runs after ea_get returns. On desktop/kiosk deployments udisks2/polkit lets an unprivileged console user mount removable media containing the crafted JFS image.\nUI:N - The attacker mounts their own crafted image and then triggers the read themselves; no victim action is needed at any point. Auto-mount of removable media likewise requires no deliberate victim interaction.\nS:U - The out-of-bounds read stays within the kernel\u0027s own address space and security authority \u2014 no VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is an unbounded slab out-of-bounds read (up to INT_MAX bytes from a 128-byte inline buffer) whose contents are hex-dumped verbatim to the kernel log, leaking adjacent heap objects, kernel pointers, and other tasks\u0027 data \u2014 far beyond a small bounded read.\nI:H - The attacker-sized dump writes tens of megabytes to gigabytes of hex output into the kernel log ring buffer, destroying all prior log and audit records; combined with the leaked heap pointers this undermines KASLR and the integrity of the system\u0027s forensic record.\nA:H - Reading hundreds of megabytes past the end of a slab object reliably walks into unmapped memory and oopses/panics the kernel, and even short of that the multi-gigabyte KERN_ERR flood renders the system unusable."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:33:54.564Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/f0dedb5c511ed82cbaff4997a8decf2351ba549f"
            },
            {
              "url": "https://git.kernel.org/stable/c/1e84c9b1838152a87cf453270a5fa75c5037e83a"
            },
            {
              "url": "https://git.kernel.org/stable/c/fc745f6e83cb650f9a5f2c864158e3a5ea76dad0"
            },
            {
              "url": "https://git.kernel.org/stable/c/480e5bc21f2c42d90c2c16045d64d824dcdd5ec7"
            },
            {
              "url": "https://git.kernel.org/stable/c/33aecc5799c93d3ee02f853cb94e201f9731f123"
            },
            {
              "url": "https://git.kernel.org/stable/c/4598233d9748fe4db4e13b9f473588aa25e87d69"
            },
            {
              "url": "https://git.kernel.org/stable/c/b537cb2f4c4a1357479716a9c339c0bda03d873f"
            },
            {
              "url": "https://git.kernel.org/stable/c/7c55b78818cfb732680c4a72ab270cc2d2ee3d0f"
            }
          ],
          "title": "jfs: xattr: fix buffer overflow for invalid xattr",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-40902",
        "datePublished": "2024-07-12T12:20:43.508Z",
        "dateReserved": "2024-07-12T12:17:45.579Z",
        "dateUpdated": "2026-08-05T11:33:54.564Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-39495 (GCVE-0-2024-39495)

    Vulnerability from cvelistv5 – Published: 2024-07-12 12:20 – Updated: 2026-08-05 11:33
    VLAI
    Title
    greybus: Fix use-after-free bug in gb_interface_release due to race condition.
    Summary
    In the Linux kernel, the following vulnerability has been resolved: greybus: Fix use-after-free bug in gb_interface_release due to race condition. In gb_interface_create, &intf->mode_switch_completion is bound with gb_interface_mode_switch_work. Then it will be started by gb_interface_request_mode_switch. Here is the relevant code. if (!queue_work(system_long_wq, &intf->mode_switch_work)) { ... } If we call gb_interface_release to make cleanup, there may be an unfinished work. This function will call kfree to free the object "intf". However, if gb_interface_mode_switch_work is scheduled to run after kfree, it may cause use-after-free error as gb_interface_mode_switch_work will use the object "intf". The possible execution flow that may lead to the issue is as follows: CPU0 CPU1 | gb_interface_create | gb_interface_request_mode_switch gb_interface_release | kfree(intf) (free) | | gb_interface_mode_switch_work | mutex_lock(&intf->mutex) (use) Fix it by canceling the work before kfree.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-16 04:02 UTC
    CWE
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 55742d2a071a569bf20f90d37b1b5b8a25a3f882 , < 74cd0a421896b2e07eafe7da4275302bfecef201 (git)
    Affected: 55742d2a071a569bf20f90d37b1b5b8a25a3f882 , < 2b6bb0b4abfd79b8698ee161bb73c0936a2aaf83 (git)
    Affected: 55742d2a071a569bf20f90d37b1b5b8a25a3f882 , < fb071f5c75d4b1c177824de74ee75f9dd34123b9 (git)
    Affected: 55742d2a071a569bf20f90d37b1b5b8a25a3f882 , < 9a733d69a4a59c2d08620e6589d823c24be773dc (git)
    Affected: 55742d2a071a569bf20f90d37b1b5b8a25a3f882 , < 0b8fba38bdfb848fac52e71270b2aa3538c996ea (git)
    Affected: 55742d2a071a569bf20f90d37b1b5b8a25a3f882 , < 03ea2b129344152157418929f06726989efc0445 (git)
    Affected: 55742d2a071a569bf20f90d37b1b5b8a25a3f882 , < 5c9c5d7f26acc2c669c1dcf57d1bb43ee99220ce (git)
    Create a notification for this product.
    Linux Linux Affected: 4.9
    Unaffected: 0 , < 4.9 (semver)
    Unaffected: 5.4.279 , ≤ 5.4.* (semver)
    Unaffected: 5.10.221 , ≤ 5.10.* (semver)
    Unaffected: 5.15.162 , ≤ 5.15.* (semver)
    Unaffected: 6.1.95 , ≤ 6.1.* (semver)
    Unaffected: 6.6.35 , ≤ 6.6.* (semver)
    Unaffected: 6.9.6 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 0 , < 74cd0a421896 (git)
    Affected: 1da177e4c3f4 , < 2b6bb0b4abfd (git)
    Affected: 1da177e4c3f4 , < fb071f5c75d4 (git)
    Affected: 1da177e4c3f4 , < 9a733d69a4a5 (git)
    Affected: 1da177e4c3f4 , < 0b8fba38bdfb (git)
    Affected: 1da177e4c3f4 , < 03ea2b129344 (git)
    Affected: 1da177e4c3f4 , < 5c9c5d7f26ac (git)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T21:56:12.660Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/74cd0a421896b2e07eafe7da4275302bfecef201"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/2b6bb0b4abfd79b8698ee161bb73c0936a2aaf83"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/fb071f5c75d4b1c177824de74ee75f9dd34123b9"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/9a733d69a4a59c2d08620e6589d823c24be773dc"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/0b8fba38bdfb848fac52e71270b2aa3538c996ea"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/03ea2b129344152157418929f06726989efc0445"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/5c9c5d7f26acc2c669c1dcf57d1bb43ee99220ce"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "74cd0a421896",
                    "status": "affected",
                    "version": "0",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "2b6bb0b4abfd",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "fb071f5c75d4",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "9a733d69a4a5",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "0b8fba38bdfb",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "03ea2b129344",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5c9c5d7f26ac",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-39495",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-16T04:02:11.550513Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-20T14:16:51.245Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/greybus/interface.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "74cd0a421896b2e07eafe7da4275302bfecef201",
                  "status": "affected",
                  "version": "55742d2a071a569bf20f90d37b1b5b8a25a3f882",
                  "versionType": "git"
                },
                {
                  "lessThan": "2b6bb0b4abfd79b8698ee161bb73c0936a2aaf83",
                  "status": "affected",
                  "version": "55742d2a071a569bf20f90d37b1b5b8a25a3f882",
                  "versionType": "git"
                },
                {
                  "lessThan": "fb071f5c75d4b1c177824de74ee75f9dd34123b9",
                  "status": "affected",
                  "version": "55742d2a071a569bf20f90d37b1b5b8a25a3f882",
                  "versionType": "git"
                },
                {
                  "lessThan": "9a733d69a4a59c2d08620e6589d823c24be773dc",
                  "status": "affected",
                  "version": "55742d2a071a569bf20f90d37b1b5b8a25a3f882",
                  "versionType": "git"
                },
                {
                  "lessThan": "0b8fba38bdfb848fac52e71270b2aa3538c996ea",
                  "status": "affected",
                  "version": "55742d2a071a569bf20f90d37b1b5b8a25a3f882",
                  "versionType": "git"
                },
                {
                  "lessThan": "03ea2b129344152157418929f06726989efc0445",
                  "status": "affected",
                  "version": "55742d2a071a569bf20f90d37b1b5b8a25a3f882",
                  "versionType": "git"
                },
                {
                  "lessThan": "5c9c5d7f26acc2c669c1dcf57d1bb43ee99220ce",
                  "status": "affected",
                  "version": "55742d2a071a569bf20f90d37b1b5b8a25a3f882",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/greybus/interface.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.9"
                },
                {
                  "lessThan": "4.9",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.279",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.221",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.162",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.95",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.35",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.6",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.279",
                      "versionStartIncluding": "4.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.221",
                      "versionStartIncluding": "4.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.162",
                      "versionStartIncluding": "4.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.95",
                      "versionStartIncluding": "4.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.35",
                      "versionStartIncluding": "4.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.6",
                      "versionStartIncluding": "4.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "4.9",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngreybus: Fix use-after-free bug in gb_interface_release due to race condition.\n\nIn gb_interface_create, \u0026intf-\u003emode_switch_completion is bound with\ngb_interface_mode_switch_work. Then it will be started by\ngb_interface_request_mode_switch. Here is the relevant code.\nif (!queue_work(system_long_wq, \u0026intf-\u003emode_switch_work)) {\n\t...\n}\n\nIf we call gb_interface_release to make cleanup, there may be an\nunfinished work. This function will call kfree to free the object\n\"intf\". However, if gb_interface_mode_switch_work is scheduled to\nrun after kfree, it may cause use-after-free error as\ngb_interface_mode_switch_work will use the object \"intf\".\nThe possible execution flow that may lead to the issue is as follows:\n\nCPU0                            CPU1\n\n                            |   gb_interface_create\n                            |   gb_interface_request_mode_switch\ngb_interface_release        |\nkfree(intf) (free)          |\n                            |   gb_interface_mode_switch_work\n                            |   mutex_lock(\u0026intf-\u003emutex) (use)\n\nFix it by canceling the work before kfree."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The attacker-controlled side of the race is the FW_MGMT_IOC_MODE_SWITCH ioctl on the /dev/gb-fw-mgmt-N character device (drivers/staging/greybus/fw-management.c:503), the sole caller of gb_interface_request_mode_switch(). Greybus is a local bus (USB/UART/serdev transport), not remotely reachable, so exploitation requires local access to the system.\nAC:L - The attacker directly controls the work-queueing side via the ioctl and can retry it in a tight loop indefinitely, while the free side (interface refcount drop via module removal / SVC teardown) can be induced repeatedly by hot-unplug or the 2-second mode-switch timeout path that calls gb_interface_deactivate(). Heap grooming of the ~1KB gb_interface allocation is standard, so the attacker creates and wins the race himself rather than depending on conditions outside his control.\nPR:L - fw_mgmt_ioctl() and fw_mgmt_ioctl_unlocked() contain no capable() or CAP_* check at all; the only gate is the permission on the /dev/gb-fw-mgmt-N node, which on greybus-based embedded/mobile deployments is routinely granted to a non-root firmware-management service or group. An unprivileged user holding a descriptor to that node can drive the entire path.\nUI:N - No victim action is needed \u2014 the attacker issues the ioctl himself, and the freeing side is driven by SVC module-removed events or the mode-switch timeout that the attacker can provoke. No file must be opened and no filesystem mounted by another user.\nS:U - The use-after-free corrupts kernel heap memory and is exploited within the same kernel security authority; there is no hypervisor, IOMMU, or sandbox boundary crossed. This is standard local kernel privilege escalation.\nC:H - The freed gb_interface can be reclaimed and sprayed by the attacker, after which gb_interface_mode_switch_work() reads intf-\u003econtrol, intf-\u003eenabled and walks intf-\u003ebundles, giving a controlled-pointer dereference usable as an arbitrary kernel-memory read primitive. Full disclosure of kernel memory, including credentials and KASLR-defeating pointers, is achievable.\nI:H - mutex_lock(\u0026intf-\u003emutex) on the freed object writes into attacker-controlled reclaimed memory, and gb_bundle_destroy() iterating the stale intf-\u003ebundles list performs list-unlink writes through attacker-supplied pointers. These are classic UAF write primitives that can be escalated to control-flow hijack and full kernel compromise.\nA:H - Even without successful reclaim, the work item dereferences and takes a mutex on freed memory, producing a kernel oops or panic. Any use-after-free of this kind reliably crashes the system, and the ioctl can be repeated to trigger it at will."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:33:44.931Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/74cd0a421896b2e07eafe7da4275302bfecef201"
            },
            {
              "url": "https://git.kernel.org/stable/c/2b6bb0b4abfd79b8698ee161bb73c0936a2aaf83"
            },
            {
              "url": "https://git.kernel.org/stable/c/fb071f5c75d4b1c177824de74ee75f9dd34123b9"
            },
            {
              "url": "https://git.kernel.org/stable/c/9a733d69a4a59c2d08620e6589d823c24be773dc"
            },
            {
              "url": "https://git.kernel.org/stable/c/0b8fba38bdfb848fac52e71270b2aa3538c996ea"
            },
            {
              "url": "https://git.kernel.org/stable/c/03ea2b129344152157418929f06726989efc0445"
            },
            {
              "url": "https://git.kernel.org/stable/c/5c9c5d7f26acc2c669c1dcf57d1bb43ee99220ce"
            }
          ],
          "title": "greybus: Fix use-after-free bug in gb_interface_release due to race condition.",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-39495",
        "datePublished": "2024-07-12T12:20:31.022Z",
        "dateReserved": "2024-06-25T14:23:23.751Z",
        "dateUpdated": "2026-08-05T11:33:44.931Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-39480 (GCVE-0-2024-39480)

    Vulnerability from cvelistv5 – Published: 2024-07-05 06:55 – Updated: 2026-08-05 11:33
    VLAI
    Title
    kdb: Fix buffer overflow during tab-complete
    Summary
    In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete Currently, when the user attempts symbol completion with the Tab key, kdb will use strncpy() to insert the completed symbol into the command buffer. Unfortunately it passes the size of the source buffer rather than the destination to strncpy() with predictably horrible results. Most obviously if the command buffer is already full but cp, the cursor position, is in the middle of the buffer, then we will write past the end of the supplied buffer. Fix this by replacing the dubious strncpy() calls with memmove()/memcpy() calls plus explicit boundary checks to make sure we have enough space before we start moving characters around.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-20 03:55 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 5d5314d6795f3c1c0f415348ff8c51f7de042b77 , < fb824a99e148ff272a53d71d84122728b5f00992 (git)
    Affected: 5d5314d6795f3c1c0f415348ff8c51f7de042b77 , < ddd2972d8e2dee3b33e8121669d55def59f0be8a (git)
    Affected: 5d5314d6795f3c1c0f415348ff8c51f7de042b77 , < cfdc2fa4db57503bc6d3817240547c8ddc55fa96 (git)
    Affected: 5d5314d6795f3c1c0f415348ff8c51f7de042b77 , < f636a40834d22e5e3fc748f060211879c056cd33 (git)
    Affected: 5d5314d6795f3c1c0f415348ff8c51f7de042b77 , < 33d9c814652b971461d1e30bead6792851c209e7 (git)
    Affected: 5d5314d6795f3c1c0f415348ff8c51f7de042b77 , < 107e825cc448b7834b31e8b1b3cf0f57426d46d5 (git)
    Affected: 5d5314d6795f3c1c0f415348ff8c51f7de042b77 , < f694da720dcf795dc3eb97bf76d220213f76aaa7 (git)
    Affected: 5d5314d6795f3c1c0f415348ff8c51f7de042b77 , < e9730744bf3af04cda23799029342aa3cddbc454 (git)
    Create a notification for this product.
    Linux Linux Affected: 2.6.35
    Unaffected: 0 , < 2.6.35 (semver)
    Unaffected: 4.19.316 , ≤ 4.19.* (semver)
    Unaffected: 5.4.278 , ≤ 5.4.* (semver)
    Unaffected: 5.10.219 , ≤ 5.10.* (semver)
    Unaffected: 5.15.161 , ≤ 5.15.* (semver)
    Unaffected: 6.1.94 , ≤ 6.1.* (semver)
    Unaffected: 6.6.34 , ≤ 6.6.* (semver)
    Unaffected: 6.9.5 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < fb824a99e148 (git)
    Affected: 1da177e4c3f4 , < ddd2972d8e2d (git)
    Affected: 1da177e4c3f4 , < cfdc2fa4db57 (git)
    Affected: 1da177e4c3f4 , < f636a40834d2 (git)
    Affected: 1da177e4c3f4 , < 33d9c814652b (git)
    Affected: 1da177e4c3f4 , < 107e825cc448 (git)
    Affected: 1da177e4c3f4 , < f694da720dcf (git)
    Affected: 1da177e4c3f4 , < e9730744bf3a (git)
    Unaffected: 4.19.316 , ≤ 4.20 (git)
    Unaffected: 5.4.278 , ≤ 5.5 (git)
    Unaffected: 5.10.219 , ≤ 5.11 (git)
    Unaffected: 5.15.161 , ≤ 5.16 (git)
    Unaffected: 6.1.94 , ≤ 6.2 (git)
    Unaffected: 6.6.34 , ≤ 6.7 (git)
    Unaffected: 6.9.5 , ≤ 6.10 (git)
    Unaffected: 6.10 , ≤ * (git)
        cpe:2.3:a:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T04:26:15.655Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/fb824a99e148ff272a53d71d84122728b5f00992"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/ddd2972d8e2dee3b33e8121669d55def59f0be8a"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/cfdc2fa4db57503bc6d3817240547c8ddc55fa96"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/f636a40834d22e5e3fc748f060211879c056cd33"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/33d9c814652b971461d1e30bead6792851c209e7"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/107e825cc448b7834b31e8b1b3cf0f57426d46d5"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/f694da720dcf795dc3eb97bf76d220213f76aaa7"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/e9730744bf3af04cda23799029342aa3cddbc454"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "fb824a99e148",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "ddd2972d8e2d",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "cfdc2fa4db57",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "f636a40834d2",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "33d9c814652b",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "107e825cc448",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "f694da720dcf",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "e9730744bf3a",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "git"
                  },
                  {
                    "lessThanOrEqual": "4.20",
                    "status": "unaffected",
                    "version": "4.19.316",
                    "versionType": "git"
                  },
                  {
                    "lessThanOrEqual": "5.5",
                    "status": "unaffected",
                    "version": "5.4.278",
                    "versionType": "git"
                  },
                  {
                    "lessThanOrEqual": "5.11",
                    "status": "unaffected",
                    "version": "5.10.219",
                    "versionType": "git"
                  },
                  {
                    "lessThanOrEqual": "5.16",
                    "status": "unaffected",
                    "version": "5.15.161",
                    "versionType": "git"
                  },
                  {
                    "lessThanOrEqual": "6.2",
                    "status": "unaffected",
                    "version": "6.1.94",
                    "versionType": "git"
                  },
                  {
                    "lessThanOrEqual": "6.7",
                    "status": "unaffected",
                    "version": "6.6.34",
                    "versionType": "git"
                  },
                  {
                    "lessThanOrEqual": "6.10",
                    "status": "unaffected",
                    "version": "6.9.5",
                    "versionType": "git"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "6.10",
                    "versionType": "git"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-39480",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-20T03:55:14.759316Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-121",
                    "description": "CWE-121 Stack-based Buffer Overflow",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-27T14:14:17.550Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "kernel/debug/kdb/kdb_io.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "fb824a99e148ff272a53d71d84122728b5f00992",
                  "status": "affected",
                  "version": "5d5314d6795f3c1c0f415348ff8c51f7de042b77",
                  "versionType": "git"
                },
                {
                  "lessThan": "ddd2972d8e2dee3b33e8121669d55def59f0be8a",
                  "status": "affected",
                  "version": "5d5314d6795f3c1c0f415348ff8c51f7de042b77",
                  "versionType": "git"
                },
                {
                  "lessThan": "cfdc2fa4db57503bc6d3817240547c8ddc55fa96",
                  "status": "affected",
                  "version": "5d5314d6795f3c1c0f415348ff8c51f7de042b77",
                  "versionType": "git"
                },
                {
                  "lessThan": "f636a40834d22e5e3fc748f060211879c056cd33",
                  "status": "affected",
                  "version": "5d5314d6795f3c1c0f415348ff8c51f7de042b77",
                  "versionType": "git"
                },
                {
                  "lessThan": "33d9c814652b971461d1e30bead6792851c209e7",
                  "status": "affected",
                  "version": "5d5314d6795f3c1c0f415348ff8c51f7de042b77",
                  "versionType": "git"
                },
                {
                  "lessThan": "107e825cc448b7834b31e8b1b3cf0f57426d46d5",
                  "status": "affected",
                  "version": "5d5314d6795f3c1c0f415348ff8c51f7de042b77",
                  "versionType": "git"
                },
                {
                  "lessThan": "f694da720dcf795dc3eb97bf76d220213f76aaa7",
                  "status": "affected",
                  "version": "5d5314d6795f3c1c0f415348ff8c51f7de042b77",
                  "versionType": "git"
                },
                {
                  "lessThan": "e9730744bf3af04cda23799029342aa3cddbc454",
                  "status": "affected",
                  "version": "5d5314d6795f3c1c0f415348ff8c51f7de042b77",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "kernel/debug/kdb/kdb_io.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.6.35"
                },
                {
                  "lessThan": "2.6.35",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "4.19.*",
                  "status": "unaffected",
                  "version": "4.19.316",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.278",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.219",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.161",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.94",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.34",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.19.316",
                      "versionStartIncluding": "2.6.35",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.278",
                      "versionStartIncluding": "2.6.35",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.219",
                      "versionStartIncluding": "2.6.35",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.161",
                      "versionStartIncluding": "2.6.35",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.94",
                      "versionStartIncluding": "2.6.35",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.34",
                      "versionStartIncluding": "2.6.35",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.5",
                      "versionStartIncluding": "2.6.35",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "2.6.35",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nkdb: Fix buffer overflow during tab-complete\n\nCurrently, when the user attempts symbol completion with the Tab key, kdb\nwill use strncpy() to insert the completed symbol into the command buffer.\nUnfortunately it passes the size of the source buffer rather than the\ndestination to strncpy() with predictably horrible results. Most obviously\nif the command buffer is already full but cp, the cursor position, is in\nthe middle of the buffer, then we will write past the end of the supplied\nbuffer.\n\nFix this by replacing the dubious strncpy() calls with memmove()/memcpy()\ncalls plus explicit boundary checks to make sure we have enough space\nbefore we start moving characters around."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - kdb_read() is reachable only from the in-kernel debugger prompt, entered via Magic SysRq-\u0027g\u0027 from the physical keyboard or a BREAK on the serial console (or root via /proc/sysrq-trigger); it is not bound to the network stack. CVSS 3.1 classifies exploitation \"by accessing the target system locally (e.g., keyboard, console)\" as Local rather than Physical.\nAC:L - The attacker fully controls the input line \u2014 filling the command buffer near its 198-byte limit, repositioning the cursor mid-line, and pressing Tab deterministically drives the unbounded strncpy() past the end of cmd_cur[200] and tmpbuffer[256]. There is no race, no timing window, and no memory-layout condition outside the attacker\u0027s control.\nPR:N - The SysRq-\u0027g\u0027 console/serial entry path requires no account, login, or credentials on the target \u2014 sysrq_dbg_op has enable_mask 0 and passes on the default sysrq_enabled==1 \u2014 and a panic/oops leaves the kdb prompt open to anyone at the console. On an embedded, automotive, or appliance board with kgdboc on an exposed serial header, an unauthenticated attacker reaches the prompt directly.\nUI:N - The attacker types the over-long line and presses Tab themselves at the debugger prompt. No action by any other user or victim is needed.\nS:U - The out-of-bounds write corrupts kernel .bss within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The overflow destroys adjacent .bss contents including NUL terminators, so the subsequent kdb_printf(\"%s\", cp) walks past the buffer and dumps adjacent kernel memory to the console, and the OOB write into unguarded static memory can be further leveraged for arbitrary disclosure.\nI:H - This is an out-of-bounds write of attacker-influenced content (typed characters plus kernel symbol names) with an attacker-chosen length into static .bss buffers (cmd_cur[200], tmpbuffer[256]) that have no canary or guard page, corrupting neighbouring kernel globals and enabling control-flow-relevant corruption.\nA:H - Writing past the end of these static buffers corrupts adjacent kernel state and reliably produces oops/panic or a wedged debugger, taking the system down."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:33:34.087Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/fb824a99e148ff272a53d71d84122728b5f00992"
            },
            {
              "url": "https://git.kernel.org/stable/c/ddd2972d8e2dee3b33e8121669d55def59f0be8a"
            },
            {
              "url": "https://git.kernel.org/stable/c/cfdc2fa4db57503bc6d3817240547c8ddc55fa96"
            },
            {
              "url": "https://git.kernel.org/stable/c/f636a40834d22e5e3fc748f060211879c056cd33"
            },
            {
              "url": "https://git.kernel.org/stable/c/33d9c814652b971461d1e30bead6792851c209e7"
            },
            {
              "url": "https://git.kernel.org/stable/c/107e825cc448b7834b31e8b1b3cf0f57426d46d5"
            },
            {
              "url": "https://git.kernel.org/stable/c/f694da720dcf795dc3eb97bf76d220213f76aaa7"
            },
            {
              "url": "https://git.kernel.org/stable/c/e9730744bf3af04cda23799029342aa3cddbc454"
            }
          ],
          "title": "kdb: Fix buffer overflow during tab-complete",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-39480",
        "datePublished": "2024-07-05T06:55:09.241Z",
        "dateReserved": "2024-06-25T14:23:23.746Z",
        "dateUpdated": "2026-08-05T11:33:34.087Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-39479 (GCVE-0-2024-39479)

    Vulnerability from cvelistv5 – Published: 2024-07-05 06:55 – Updated: 2026-08-05 11:33
    VLAI
    Title
    drm/i915/hwmon: Get rid of devm
    Summary
    In the Linux kernel, the following vulnerability has been resolved: drm/i915/hwmon: Get rid of devm When both hwmon and hwmon drvdata (on which hwmon depends) are device managed resources, the expectation, on device unbind, is that hwmon will be released before drvdata. However, in i915 there are two separate code paths, which both release either drvdata or hwmon and either can be released before the other. These code paths (for device unbind) are as follows (see also the bug referenced below): Call Trace: release_nodes+0x11/0x70 devres_release_group+0xb2/0x110 component_unbind_all+0x8d/0xa0 component_del+0xa5/0x140 intel_pxp_tee_component_fini+0x29/0x40 [i915] intel_pxp_fini+0x33/0x80 [i915] i915_driver_remove+0x4c/0x120 [i915] i915_pci_remove+0x19/0x30 [i915] pci_device_remove+0x32/0xa0 device_release_driver_internal+0x19c/0x200 unbind_store+0x9c/0xb0 and Call Trace: release_nodes+0x11/0x70 devres_release_all+0x8a/0xc0 device_unbind_cleanup+0x9/0x70 device_release_driver_internal+0x1c1/0x200 unbind_store+0x9c/0xb0 This means that in i915, if use devm, we cannot gurantee that hwmon will always be released before drvdata. Which means that we have a uaf if hwmon sysfs is accessed when drvdata has been released but hwmon hasn't. The only way out of this seems to be do get rid of devm_ and release/free everything explicitly during device unbind. v2: Change commit message and other minor code changes v3: Cleanup from i915_hwmon_register on error (Armin Wolf) v4: Eliminate potential static analyzer warning (Rodrigo) Eliminate fetch_and_zero (Jani) v5: Restore previous logic for ddat_gt->hwmon_dev error return (Andi)
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-05 14:32 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    Linux Linux Affected: b3b088e28183b84080b7f0a0b8da84ec42b4b0e8 , < cfa73607eb21a4ce1d6294a2c5733628897b48a2 (git)
    Affected: b3b088e28183b84080b7f0a0b8da84ec42b4b0e8 , < ce5a22d22db691d14516c3b8fdbf69139eb2ea8f (git)
    Affected: b3b088e28183b84080b7f0a0b8da84ec42b4b0e8 , < 5bc9de065b8bb9b8dd8799ecb4592d0403b54281 (git)
    Create a notification for this product.
    Linux Linux Affected: 6.2
    Unaffected: 0 , < 6.2 (semver)
    Unaffected: 6.6.34 , ≤ 6.6.* (semver)
    Unaffected: 6.9.5 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < cfa73607eb21 (custom)
    Affected: 1da177e4c3f4 , < ce5a22d22db6 (custom)
    Affected: 1da177e4c3f4 , < 5bc9de065b8b (custom)
    Unaffected: 6.6.34 , ≤ 6.7 (custom)
    Unaffected: 6.95 , ≤ 6.10 (custom)
    Unaffected: 6.10-rc1
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "cfa73607eb21",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "ce5a22d22db6",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "5bc9de065b8b",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "6.7",
                    "status": "unaffected",
                    "version": "6.6.34",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "6.10",
                    "status": "unaffected",
                    "version": "6.95",
                    "versionType": "custom"
                  },
                  {
                    "status": "unaffected",
                    "version": "6.10-rc1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-39479",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-05T14:32:43.637731Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-05T14:38:39.208Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T04:26:15.833Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/cfa73607eb21a4ce1d6294a2c5733628897b48a2"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/ce5a22d22db691d14516c3b8fdbf69139eb2ea8f"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/5bc9de065b8bb9b8dd8799ecb4592d0403b54281"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/gpu/drm/i915/i915_hwmon.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "cfa73607eb21a4ce1d6294a2c5733628897b48a2",
                  "status": "affected",
                  "version": "b3b088e28183b84080b7f0a0b8da84ec42b4b0e8",
                  "versionType": "git"
                },
                {
                  "lessThan": "ce5a22d22db691d14516c3b8fdbf69139eb2ea8f",
                  "status": "affected",
                  "version": "b3b088e28183b84080b7f0a0b8da84ec42b4b0e8",
                  "versionType": "git"
                },
                {
                  "lessThan": "5bc9de065b8bb9b8dd8799ecb4592d0403b54281",
                  "status": "affected",
                  "version": "b3b088e28183b84080b7f0a0b8da84ec42b4b0e8",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/gpu/drm/i915/i915_hwmon.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.2"
                },
                {
                  "lessThan": "6.2",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.34",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.34",
                      "versionStartIncluding": "6.2",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.5",
                      "versionStartIncluding": "6.2",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "6.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/hwmon: Get rid of devm\n\nWhen both hwmon and hwmon drvdata (on which hwmon depends) are device\nmanaged resources, the expectation, on device unbind, is that hwmon will be\nreleased before drvdata. However, in i915 there are two separate code\npaths, which both release either drvdata or hwmon and either can be\nreleased before the other. These code paths (for device unbind) are as\nfollows (see also the bug referenced below):\n\nCall Trace:\nrelease_nodes+0x11/0x70\ndevres_release_group+0xb2/0x110\ncomponent_unbind_all+0x8d/0xa0\ncomponent_del+0xa5/0x140\nintel_pxp_tee_component_fini+0x29/0x40 [i915]\nintel_pxp_fini+0x33/0x80 [i915]\ni915_driver_remove+0x4c/0x120 [i915]\ni915_pci_remove+0x19/0x30 [i915]\npci_device_remove+0x32/0xa0\ndevice_release_driver_internal+0x19c/0x200\nunbind_store+0x9c/0xb0\n\nand\n\nCall Trace:\nrelease_nodes+0x11/0x70\ndevres_release_all+0x8a/0xc0\ndevice_unbind_cleanup+0x9/0x70\ndevice_release_driver_internal+0x1c1/0x200\nunbind_store+0x9c/0xb0\n\nThis means that in i915, if use devm, we cannot gurantee that hwmon will\nalways be released before drvdata. Which means that we have a uaf if hwmon\nsysfs is accessed when drvdata has been released but hwmon hasn\u0027t.\n\nThe only way out of this seems to be do get rid of devm_ and release/free\neverything explicitly during device unbind.\n\nv2: Change commit message and other minor code changes\nv3: Cleanup from i915_hwmon_register on error (Armin Wolf)\nv4: Eliminate potential static analyzer warning (Rodrigo)\n    Eliminate fetch_and_zero (Jani)\nv5: Restore previous logic for ddat_gt-\u003ehwmon_dev error return (Andi)"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The vulnerable code is reached by reading an i915 hwmon sysfs attribute (`/sys/class/hwmon/hwmonN/energy1_input`) on the local machine; no network or remote peer data is involved, and the heap grooming needed to weaponize the UAF also requires local execution.\nAC:L - The freed-object window is opened only by driver unbind, module removal, or PCI hot-remove \u2014 an administrative event an unprivileged attacker cannot cause \u2014 but once it occurs the attacker does not need to win a tight timing race: the hwmon sysfs nodes stay registered and readable across the entire teardown interval, so a zero-cost busy-read loop lands in the window deterministically. Choosing the higher-severity option where the two readings are defensible.\nPR:L - `energy1_input`, `in0_input` and `power1_rated_max` are mode 0444 and `power1_max_interval` is 0664, so any local unprivileged account can open and read them with no capability check anywhere on the path from `sysfs_kf_seq_show` down to `hwm_energy()`.\nUI:N - The attacker\u0027s read requires no victim action \u2014 no file must be opened on the victim\u0027s behalf, no media mounted; the driver unbind is a system/administrative event already accounted for in Attack Complexity, not exploit-time user participation.\nS:U - The use-after-free corrupts kernel heap memory within the same security authority as the kernel itself; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is a use-after-free on a ~400-byte `kmalloc-512` object: `hwmon-\u003erg.energy_status_*` and `rg.pkg_rapl_limit` are read from freed memory and used as MMIO offsets, and `ddat-\u003euncore` is a fully dereferenced stale pointer, so an attacker who reclaims the slot with controlled data obtains an arbitrary kernel/MMIO read reflected back through sysfs.\nI:H - `hwm_energy()` writes into the freed object (`ei-\u003eaccum_energy`, `ei-\u003ereg_val_prev`, and `mutex_lock(\u0026hwmon-\u003ehwmon_lock)`), and `intel_uncore_read()` performs an indirect call through `uncore-\u003efuncs.mmio_readl` loaded out of the freed allocation \u2014 a control-flow hijack primitive once the slab is reclaimed with attacker-influenced contents.\nA:H - Even unweaponized, dereferencing the freed `struct i915_hwmon` and the stale `ddat-\u003euncore` function-pointer table oopses the kernel; this is the reported symptom in the referenced Freedesktop bug, and it can be re-triggered on every unbind."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:33:32.923Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/cfa73607eb21a4ce1d6294a2c5733628897b48a2"
            },
            {
              "url": "https://git.kernel.org/stable/c/ce5a22d22db691d14516c3b8fdbf69139eb2ea8f"
            },
            {
              "url": "https://git.kernel.org/stable/c/5bc9de065b8bb9b8dd8799ecb4592d0403b54281"
            }
          ],
          "title": "drm/i915/hwmon: Get rid of devm",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-39479",
        "datePublished": "2024-07-05T06:55:08.597Z",
        "dateReserved": "2024-06-25T14:23:23.746Z",
        "dateUpdated": "2026-08-05T11:33:32.923Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-39463 (GCVE-0-2024-39463)

    Vulnerability from cvelistv5 – Published: 2024-06-25 14:25 – Updated: 2026-08-05 11:33
    VLAI
    Title
    9p: add missing locking around taking dentry fid list
    Summary
    In the Linux kernel, the following vulnerability has been resolved: 9p: add missing locking around taking dentry fid list Fix a use-after-free on dentry's d_fsdata fid list when a thread looks up a fid through dentry while another thread unlinks it: UAF thread: refcount_t: addition on 0; use-after-free. p9_fid_get linux/./include/net/9p/client.h:262 v9fs_fid_find+0x236/0x280 linux/fs/9p/fid.c:129 v9fs_fid_lookup_with_uid linux/fs/9p/fid.c:181 v9fs_fid_lookup+0xbf/0xc20 linux/fs/9p/fid.c:314 v9fs_vfs_getattr_dotl+0xf9/0x360 linux/fs/9p/vfs_inode_dotl.c:400 vfs_statx+0xdd/0x4d0 linux/fs/stat.c:248 Freed by: p9_fid_destroy (inlined) p9_client_clunk+0xb0/0xe0 linux/net/9p/client.c:1456 p9_fid_put linux/./include/net/9p/client.h:278 v9fs_dentry_release+0xb5/0x140 linux/fs/9p/vfs_dentry.c:55 v9fs_remove+0x38f/0x620 linux/fs/9p/vfs_inode.c:518 vfs_unlink+0x29a/0x810 linux/fs/namei.c:4335 The problem is that d_fsdata was not accessed under d_lock, because d_release() normally is only called once the dentry is otherwise no longer accessible but since we also call it explicitly in v9fs_remove that lock is required: move the hlist out of the dentry under lock then unref its fids once they are no longer accessible.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 03:55 UTC
    CWE
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 154372e67d4053e56591245eb413686621941333 , < 3bb6763a8319170c2d41c4232c8e7e4c37dcacfb (git)
    Affected: 154372e67d4053e56591245eb413686621941333 , < cb299cdba09f46f090b843d78ba26b667d50a456 (git)
    Affected: 154372e67d4053e56591245eb413686621941333 , < f0c5c944c6d8614c19e6e9a97fd2011dcd30e8f5 (git)
    Affected: 154372e67d4053e56591245eb413686621941333 , < fe17ebf22feb4ad7094d597526d558a49aac92b4 (git)
    Affected: 154372e67d4053e56591245eb413686621941333 , < c898afdc15645efb555acb6d85b484eb40a45409 (git)
    Create a notification for this product.
    Linux Linux Affected: 5.11
    Unaffected: 0 , < 5.11 (semver)
    Unaffected: 5.15.168 , ≤ 5.15.* (semver)
    Unaffected: 6.1.94 , ≤ 6.1.* (semver)
    Unaffected: 6.6.34 , ≤ 6.6.* (semver)
    Unaffected: 6.9.5 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 5.11
        cpe:2.3:o:linux:linux_kernel:5.11:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 154372e67d40 , < cb299cdba09f (custom)
    Affected: 154372e67d40 , < f0c5c944c6d8 (custom)
    Affected: 154372e67d40 , < fe17ebf22feb (custom)
    Affected: 154372e67d40 , < c898afdc1564 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T04:26:15.245Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/cb299cdba09f46f090b843d78ba26b667d50a456"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/f0c5c944c6d8614c19e6e9a97fd2011dcd30e8f5"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/fe17ebf22feb4ad7094d597526d558a49aac92b4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/c898afdc15645efb555acb6d85b484eb40a45409"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:5.11:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.11"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "cb299cdba09f",
                    "status": "affected",
                    "version": "154372e67d40",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "f0c5c944c6d8",
                    "status": "affected",
                    "version": "154372e67d40",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "fe17ebf22feb",
                    "status": "affected",
                    "version": "154372e67d40",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "c898afdc1564",
                    "status": "affected",
                    "version": "154372e67d40",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-39463",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T03:55:21.281977Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-10T15:36:18.860Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "fs/9p/vfs_dentry.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "3bb6763a8319170c2d41c4232c8e7e4c37dcacfb",
                  "status": "affected",
                  "version": "154372e67d4053e56591245eb413686621941333",
                  "versionType": "git"
                },
                {
                  "lessThan": "cb299cdba09f46f090b843d78ba26b667d50a456",
                  "status": "affected",
                  "version": "154372e67d4053e56591245eb413686621941333",
                  "versionType": "git"
                },
                {
                  "lessThan": "f0c5c944c6d8614c19e6e9a97fd2011dcd30e8f5",
                  "status": "affected",
                  "version": "154372e67d4053e56591245eb413686621941333",
                  "versionType": "git"
                },
                {
                  "lessThan": "fe17ebf22feb4ad7094d597526d558a49aac92b4",
                  "status": "affected",
                  "version": "154372e67d4053e56591245eb413686621941333",
                  "versionType": "git"
                },
                {
                  "lessThan": "c898afdc15645efb555acb6d85b484eb40a45409",
                  "status": "affected",
                  "version": "154372e67d4053e56591245eb413686621941333",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "fs/9p/vfs_dentry.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.11"
                },
                {
                  "lessThan": "5.11",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.168",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.94",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.34",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.168",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.94",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.34",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.5",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\n9p: add missing locking around taking dentry fid list\n\nFix a use-after-free on dentry\u0027s d_fsdata fid list when a thread\nlooks up a fid through dentry while another thread unlinks it:\n\nUAF thread:\nrefcount_t: addition on 0; use-after-free.\n p9_fid_get linux/./include/net/9p/client.h:262\n v9fs_fid_find+0x236/0x280 linux/fs/9p/fid.c:129\n v9fs_fid_lookup_with_uid linux/fs/9p/fid.c:181\n v9fs_fid_lookup+0xbf/0xc20 linux/fs/9p/fid.c:314\n v9fs_vfs_getattr_dotl+0xf9/0x360 linux/fs/9p/vfs_inode_dotl.c:400\n vfs_statx+0xdd/0x4d0 linux/fs/stat.c:248\n\nFreed by:\n p9_fid_destroy (inlined)\n p9_client_clunk+0xb0/0xe0 linux/net/9p/client.c:1456\n p9_fid_put linux/./include/net/9p/client.h:278\n v9fs_dentry_release+0xb5/0x140 linux/fs/9p/vfs_dentry.c:55\n v9fs_remove+0x38f/0x620 linux/fs/9p/vfs_inode.c:518\n vfs_unlink+0x29a/0x810 linux/fs/namei.c:4335\n\nThe problem is that d_fsdata was not accessed under d_lock, because\nd_release() normally is only called once the dentry is otherwise no\nlonger accessible but since we also call it explicitly in v9fs_remove\nthat lock is required:\nmove the hlist out of the dentry under lock then unref its fids once\nthey are no longer accessible."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The race is triggered entirely through local syscalls (`statx()`/`getxattr()` and `unlink()`) issued against a mounted 9p filesystem; no network peer input is required to reach the vulnerable code.\nAC:L - The attacker controls both sides of the race by running two threads (one looping statx, one looping unlink) on the same path, and the window is exceptionally wide because the freed fid remains linked in `d_fsdata` for the entire blocking TCLUNK RPC round-trip; nothing in VFS serializes statx against vfs_unlink.\nPR:L - An unprivileged local user with access to an existing 9p mount (QEMU virtfs share, WSL2, Crostini, Kata/LXD VM guests) can trigger this \u2014 both statx and unlink are unprivileged operations needing only write permission on a directory the user already owns.\nUI:N - The attacker performs both racing operations themselves; no victim action is required, as the 9p mount is a pre-existing deployment property rather than an action induced from a user.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security authority; it yields local kernel privilege escalation, not a crossing of a VM/IOMMU boundary.\nC:H - The dangling `struct p9_fid` comes from a general kmalloc slab and is dereferenced after free (`fid-\u003eclnt`, `fid-\u003efid`), so heap reclamation gives the attacker a read primitive over adjacent/reclaimed kernel objects and disclosure of kernel pointers.\nI:H - The UAF provides refcount writes into freed memory, a controlled `fid-\u003eclnt` pointer dereference used for spinlock/`idr_remove()` operations, a `kfree(fid-\u003erdir)` arbitrary-free, and a double free \u2014 a classic path to arbitrary write and control-flow hijack.\nA:H - Even unweaponized, the bug produces a `refcount_t: addition on 0` splat, slab corruption, and kernel oops/panic, and can be triggered repeatedly by any local user with access to the mount."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:33:24.281Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/3bb6763a8319170c2d41c4232c8e7e4c37dcacfb"
            },
            {
              "url": "https://git.kernel.org/stable/c/cb299cdba09f46f090b843d78ba26b667d50a456"
            },
            {
              "url": "https://git.kernel.org/stable/c/f0c5c944c6d8614c19e6e9a97fd2011dcd30e8f5"
            },
            {
              "url": "https://git.kernel.org/stable/c/fe17ebf22feb4ad7094d597526d558a49aac92b4"
            },
            {
              "url": "https://git.kernel.org/stable/c/c898afdc15645efb555acb6d85b484eb40a45409"
            },
            {
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1194/"
            }
          ],
          "title": "9p: add missing locking around taking dentry fid list",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-39463",
        "datePublished": "2024-06-25T14:25:02.887Z",
        "dateReserved": "2024-06-25T14:23:23.744Z",
        "dateUpdated": "2026-08-05T11:33:24.281Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-39462 (GCVE-0-2024-39462)

    Vulnerability from cvelistv5 – Published: 2024-06-25 14:25 – Updated: 2026-05-11 20:21
    VLAI
    Title
    clk: bcm: dvp: Assign ->num before accessing ->hws
    Summary
    In the Linux kernel, the following vulnerability has been resolved: clk: bcm: dvp: Assign ->num before accessing ->hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with __counted_by") annotated the hws member of 'struct clk_hw_onecell_data' with __counted_by, which informs the bounds sanitizer about the number of elements in hws, so that it can warn when hws is accessed out of bounds. As noted in that change, the __counted_by member must be initialized with the number of elements before the first array access happens, otherwise there will be a warning from each access prior to the initialization because the number of elements is zero. This occurs in clk_dvp_probe() due to ->num being assigned after ->hws has been accessed: UBSAN: array-index-out-of-bounds in drivers/clk/bcm/clk-bcm2711-dvp.c:59:2 index 0 is out of range for type 'struct clk_hw *[] __counted_by(num)' (aka 'struct clk_hw *[]') Move the ->num initialization to before the first access of ->hws, which clears up the warning.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-25 17:03 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    Linux Linux Affected: f316cdff8d677db9ad9c90acb44c4cd535b0ee27 , < 0dc913217fb79096597005bba9ba738e2db5cd02 (git)
    Affected: f316cdff8d677db9ad9c90acb44c4cd535b0ee27 , < a1dd92fca0d6b58b55ed0484f75d4205dbb77010 (git)
    Affected: f316cdff8d677db9ad9c90acb44c4cd535b0ee27 , < 9368cdf90f52a68120d039887ccff74ff33b4444 (git)
    Create a notification for this product.
    Linux Linux Affected: 6.6
    Unaffected: 0 , < 6.6 (semver)
    Unaffected: 6.6.34 , ≤ 6.6.* (semver)
    Unaffected: 6.9.5 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 6.6
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: f316cdff8d67 , < 0dc913217fb7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: f316cdff8d67 , < a1dd92fca0d6 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: f316cdff8d67 , < 9368cdf90f52 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 6.6 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.34 , ≤ 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9.5 , ≤ 6.10 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.10-rc1
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.6"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "0dc913217fb7",
                    "status": "affected",
                    "version": "f316cdff8d67",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "a1dd92fca0d6",
                    "status": "affected",
                    "version": "f316cdff8d67",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "9368cdf90f52",
                    "status": "affected",
                    "version": "f316cdff8d67",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.6",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.7",
                    "status": "unaffected",
                    "version": "6.6.34",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.10",
                    "status": "unaffected",
                    "version": "6.9.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.10-rc1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-39462",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-25T17:03:11.356077Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-25T17:13:58.741Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T04:26:14.280Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/0dc913217fb79096597005bba9ba738e2db5cd02"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/a1dd92fca0d6b58b55ed0484f75d4205dbb77010"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/9368cdf90f52a68120d039887ccff74ff33b4444"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/clk/bcm/clk-bcm2711-dvp.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "0dc913217fb79096597005bba9ba738e2db5cd02",
                  "status": "affected",
                  "version": "f316cdff8d677db9ad9c90acb44c4cd535b0ee27",
                  "versionType": "git"
                },
                {
                  "lessThan": "a1dd92fca0d6b58b55ed0484f75d4205dbb77010",
                  "status": "affected",
                  "version": "f316cdff8d677db9ad9c90acb44c4cd535b0ee27",
                  "versionType": "git"
                },
                {
                  "lessThan": "9368cdf90f52a68120d039887ccff74ff33b4444",
                  "status": "affected",
                  "version": "f316cdff8d677db9ad9c90acb44c4cd535b0ee27",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/clk/bcm/clk-bcm2711-dvp.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.6"
                },
                {
                  "lessThan": "6.6",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.34",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.34",
                      "versionStartIncluding": "6.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.5",
                      "versionStartIncluding": "6.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "6.6",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: bcm: dvp: Assign -\u003enum before accessing -\u003ehws\n\nCommit f316cdff8d67 (\"clk: Annotate struct clk_hw_onecell_data with\n__counted_by\") annotated the hws member of \u0027struct clk_hw_onecell_data\u0027\nwith __counted_by, which informs the bounds sanitizer about the number\nof elements in hws, so that it can warn when hws is accessed out of\nbounds. As noted in that change, the __counted_by member must be\ninitialized with the number of elements before the first array access\nhappens, otherwise there will be a warning from each access prior to the\ninitialization because the number of elements is zero. This occurs in\nclk_dvp_probe() due to -\u003enum being assigned after -\u003ehws has been\naccessed:\n\n  UBSAN: array-index-out-of-bounds in drivers/clk/bcm/clk-bcm2711-dvp.c:59:2\n  index 0 is out of range for type \u0027struct clk_hw *[] __counted_by(num)\u0027 (aka \u0027struct clk_hw *[]\u0027)\n\nMove the -\u003enum initialization to before the first access of -\u003ehws, which\nclears up the warning."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T20:21:00.436Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/0dc913217fb79096597005bba9ba738e2db5cd02"
            },
            {
              "url": "https://git.kernel.org/stable/c/a1dd92fca0d6b58b55ed0484f75d4205dbb77010"
            },
            {
              "url": "https://git.kernel.org/stable/c/9368cdf90f52a68120d039887ccff74ff33b4444"
            }
          ],
          "title": "clk: bcm: dvp: Assign -\u003enum before accessing -\u003ehws",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-39462",
        "datePublished": "2024-06-25T14:25:02.196Z",
        "dateReserved": "2024-06-25T14:23:23.744Z",
        "dateUpdated": "2026-05-11T20:21:00.436Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2021-4440 (GCVE-0-2021-4440)

    Vulnerability from cvelistv5 – Published: 2024-06-25 14:20 – Updated: 2026-05-11 13:43
    VLAI
    Title
    x86/xen: Drop USERGS_SYSRET64 paravirt call
    Summary
    In the Linux kernel, the following vulnerability has been resolved: x86/xen: Drop USERGS_SYSRET64 paravirt call commit afd30525a659ac0ae0904f0cb4a2ca75522c3123 upstream. USERGS_SYSRET64 is used to return from a syscall via SYSRET, but a Xen PV guest will nevertheless use the IRET hypercall, as there is no sysret PV hypercall defined. So instead of testing all the prerequisites for doing a sysret and then mangling the stack for Xen PV again for doing an iret just use the iret exit from the beginning. This can easily be done via an ALTERNATIVE like it is done for the sysenter compat case already. It should be noted that this drops the optimization in Xen for not restoring a few registers when returning to user mode, but it seems as if the saved instructions in the kernel more than compensate for this drop (a kernel build in a Xen PV guest was slightly faster with this patch applied). While at it remove the stale sysret32 remnants. [ pawan: Brad Spengler and Salvatore Bonaccorso <carnil@debian.org> reported a problem with the 5.10 backport commit edc702b4a820 ("x86/entry_64: Add VERW just before userspace transition"). When CONFIG_PARAVIRT_XXL=y, CLEAR_CPU_BUFFERS is not executed in syscall_return_via_sysret path as USERGS_SYSRET64 is runtime patched to: .cpu_usergs_sysret64 = { 0x0f, 0x01, 0xf8, 0x48, 0x0f, 0x07 }, // swapgs; sysretq which is missing CLEAR_CPU_BUFFERS. It turns out dropping USERGS_SYSRET64 simplifies the code, allowing CLEAR_CPU_BUFFERS to be explicitly added to syscall_return_via_sysret path. Below is with CONFIG_PARAVIRT_XXL=y and this patch applied: syscall_return_via_sysret: ... <+342>: swapgs <+345>: xchg %ax,%ax <+347>: verw -0x1a2(%rip) <------ <+354>: sysretq ]
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-26 13:55 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    Linux Linux Affected: cea750c99d8f6391080c420f811a46b21bad7cf4 , < 1424ab4bb386df9cc590c73afa55f13e9b00dea2 (git)
    Create a notification for this product.
    Linux Linux Affected: 5.10.215 , < 5.10.218 (semver)
    Create a notification for this product.
    linux linux_kernel Affected: cea750c99d8f , < 1424ab4bb386 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 5.10.215 , < 5.10.218 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "1424ab4bb386",
                    "status": "affected",
                    "version": "cea750c99d8f",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.10.218",
                    "status": "affected",
                    "version": "5.10.215",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "CHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2021-4440",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-26T13:55:14.340611Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-26T14:00:48.356Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T17:30:07.494Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/1424ab4bb386df9cc590c73afa55f13e9b00dea2"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://grsecurity.net/cve-2021-4440_linux_cna_case_study"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "arch/x86/entry/entry_64.S",
                "arch/x86/include/asm/irqflags.h",
                "arch/x86/include/asm/paravirt.h",
                "arch/x86/include/asm/paravirt_types.h",
                "arch/x86/kernel/asm-offsets_64.c",
                "arch/x86/kernel/paravirt.c",
                "arch/x86/kernel/paravirt_patch.c",
                "arch/x86/xen/enlighten_pv.c",
                "arch/x86/xen/xen-asm.S",
                "arch/x86/xen/xen-ops.h"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "1424ab4bb386df9cc590c73afa55f13e9b00dea2",
                  "status": "affected",
                  "version": "cea750c99d8f6391080c420f811a46b21bad7cf4",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "arch/x86/entry/entry_64.S",
                "arch/x86/include/asm/irqflags.h",
                "arch/x86/include/asm/paravirt.h",
                "arch/x86/include/asm/paravirt_types.h",
                "arch/x86/kernel/asm-offsets_64.c",
                "arch/x86/kernel/paravirt.c",
                "arch/x86/kernel/paravirt_patch.c",
                "arch/x86/xen/enlighten_pv.c",
                "arch/x86/xen/xen-asm.S",
                "arch/x86/xen/xen-ops.h"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "5.10.218",
                  "status": "affected",
                  "version": "5.10.215",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.218",
                      "versionStartIncluding": "5.10.215",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/xen: Drop USERGS_SYSRET64 paravirt call\n\ncommit afd30525a659ac0ae0904f0cb4a2ca75522c3123 upstream.\n\nUSERGS_SYSRET64 is used to return from a syscall via SYSRET, but\na Xen PV guest will nevertheless use the IRET hypercall, as there\nis no sysret PV hypercall defined.\n\nSo instead of testing all the prerequisites for doing a sysret and\nthen mangling the stack for Xen PV again for doing an iret just use\nthe iret exit from the beginning.\n\nThis can easily be done via an ALTERNATIVE like it is done for the\nsysenter compat case already.\n\nIt should be noted that this drops the optimization in Xen for not\nrestoring a few registers when returning to user mode, but it seems\nas if the saved instructions in the kernel more than compensate for\nthis drop (a kernel build in a Xen PV guest was slightly faster with\nthis patch applied).\n\nWhile at it remove the stale sysret32 remnants.\n\n  [ pawan: Brad Spengler and Salvatore Bonaccorso \u003ccarnil@debian.org\u003e\n\t   reported a problem with the 5.10 backport commit edc702b4a820\n\t   (\"x86/entry_64: Add VERW just before userspace transition\").\n\n\t   When CONFIG_PARAVIRT_XXL=y, CLEAR_CPU_BUFFERS is not executed in\n\t   syscall_return_via_sysret path as USERGS_SYSRET64 is runtime\n\t   patched to:\n\n\t.cpu_usergs_sysret64    = { 0x0f, 0x01, 0xf8,\n\t\t\t\t    0x48, 0x0f, 0x07 }, // swapgs; sysretq\n\n\t   which is missing CLEAR_CPU_BUFFERS. It turns out dropping\n\t   USERGS_SYSRET64 simplifies the code, allowing CLEAR_CPU_BUFFERS\n\t   to be explicitly added to syscall_return_via_sysret path. Below\n\t   is with CONFIG_PARAVIRT_XXL=y and this patch applied:\n\n\t   syscall_return_via_sysret:\n\t   ...\n\t   \u003c+342\u003e:   swapgs\n\t   \u003c+345\u003e:   xchg   %ax,%ax\n\t   \u003c+347\u003e:   verw   -0x1a2(%rip)  \u003c------\n\t   \u003c+354\u003e:   sysretq\n  ]"
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T13:43:58.741Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/1424ab4bb386df9cc590c73afa55f13e9b00dea2"
            },
            {
              "url": "https://grsecurity.net/cve-2021-4440_linux_cna_case_study"
            }
          ],
          "title": "x86/xen: Drop USERGS_SYSRET64 paravirt call",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2021-4440",
        "datePublished": "2024-06-25T14:20:00.740Z",
        "dateReserved": "2024-06-25T14:16:59.867Z",
        "dateUpdated": "2026-05-11T13:43:58.741Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-34027 (GCVE-0-2024-34027)

    Vulnerability from cvelistv5 – Published: 2024-06-24 13:56 – Updated: 2026-08-05 11:29
    VLAI
    Title
    f2fs: compress: fix to cover {reserve,release}_compress_blocks() w/ cp_rwsem lock
    Summary
    In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to cover {reserve,release}_compress_blocks() w/ cp_rwsem lock It needs to cover {reserve,release}_compress_blocks() w/ cp_rwsem lock to avoid racing with checkpoint, otherwise, filesystem metadata including blkaddr in dnode, inode fields and .total_valid_block_count may be corrupted after SPO case.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-05 14:50 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    Linux Linux Affected: ef8d563f184e1112651f2cbde383d43e599334e8 , < a6e1f7744e9b84f86a629a76024bba8468aa153b (git)
    Affected: ef8d563f184e1112651f2cbde383d43e599334e8 , < b5bac43875aa27ec032dbbb86173baae6dce6182 (git)
    Affected: ef8d563f184e1112651f2cbde383d43e599334e8 , < 5d47d63883735718825ca2efc4fca6915469774f (git)
    Affected: ef8d563f184e1112651f2cbde383d43e599334e8 , < 329edb7c9e3b6ca27e6ca67ab1cdda1740fb3a2b (git)
    Affected: ef8d563f184e1112651f2cbde383d43e599334e8 , < 69136304fd144144a4828c7b7b149d0f80321ba4 (git)
    Affected: ef8d563f184e1112651f2cbde383d43e599334e8 , < 0a4ed2d97cb6d044196cc3e726b6699222b41019 (git)
    Create a notification for this product.
    Linux Linux Affected: 5.8
    Unaffected: 0 , < 5.8 (semver)
    Unaffected: 5.10.219 , ≤ 5.10.* (semver)
    Unaffected: 5.15.161 , ≤ 5.15.* (semver)
    Unaffected: 6.1.93 , ≤ 6.1.* (semver)
    Unaffected: 6.6.33 , ≤ 6.6.* (semver)
    Unaffected: 6.9.4 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: c75488fb4d82 , < a6e1f7744e9b (git)
    Affected: c75488fb4d82 , < b5bac43875aa (git)
    Affected: c75488fb4d82 , < 5d47d6388373 (git)
    Affected: c75488fb4d82 , < 329edb7c9e3b (git)
    Affected: c75488fb4d82 , < 69136304fd14 (git)
    Affected: c75488fb4d82 , < 0a4ed2d97cb6 (git)
    Affected: 5.8
    Affected: 0 , < 5.8 (semver)
    Affected: 5.10.219 , ≤ 5.10* (semver)
    Affected: 6.1.93 , ≤ 6.1* (semver)
    Affected: 6.6.33 , ≤ 6.6* (semver)
    Affected: 6.94 , ≤ 6.9* (semver)
    Affected: 6.10 , ≤ * (semver)
    Affected: 5.15.161 , ≤ 5.15* (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "a6e1f7744e9b",
                    "status": "affected",
                    "version": "c75488fb4d82",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b5bac43875aa",
                    "status": "affected",
                    "version": "c75488fb4d82",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5d47d6388373",
                    "status": "affected",
                    "version": "c75488fb4d82",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "329edb7c9e3b",
                    "status": "affected",
                    "version": "c75488fb4d82",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "69136304fd14",
                    "status": "affected",
                    "version": "c75488fb4d82",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "0a4ed2d97cb6",
                    "status": "affected",
                    "version": "c75488fb4d82",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "5.8"
                  },
                  {
                    "lessThan": "5.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.10*",
                    "status": "affected",
                    "version": "5.10.219",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1*",
                    "status": "affected",
                    "version": "6.1.93",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6*",
                    "status": "affected",
                    "version": "6.6.33",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.9*",
                    "status": "affected",
                    "version": "6.94",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "6.10",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.15*",
                    "status": "affected",
                    "version": "5.15.161",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-34027",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-05T14:50:20.784869Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-770",
                    "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-05T15:02:49.178Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T02:42:59.794Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/a6e1f7744e9b84f86a629a76024bba8468aa153b"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/b5bac43875aa27ec032dbbb86173baae6dce6182"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/5d47d63883735718825ca2efc4fca6915469774f"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/329edb7c9e3b6ca27e6ca67ab1cdda1740fb3a2b"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/69136304fd144144a4828c7b7b149d0f80321ba4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/0a4ed2d97cb6d044196cc3e726b6699222b41019"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T11:51:57.302Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "fs/f2fs/file.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "a6e1f7744e9b84f86a629a76024bba8468aa153b",
                  "status": "affected",
                  "version": "ef8d563f184e1112651f2cbde383d43e599334e8",
                  "versionType": "git"
                },
                {
                  "lessThan": "b5bac43875aa27ec032dbbb86173baae6dce6182",
                  "status": "affected",
                  "version": "ef8d563f184e1112651f2cbde383d43e599334e8",
                  "versionType": "git"
                },
                {
                  "lessThan": "5d47d63883735718825ca2efc4fca6915469774f",
                  "status": "affected",
                  "version": "ef8d563f184e1112651f2cbde383d43e599334e8",
                  "versionType": "git"
                },
                {
                  "lessThan": "329edb7c9e3b6ca27e6ca67ab1cdda1740fb3a2b",
                  "status": "affected",
                  "version": "ef8d563f184e1112651f2cbde383d43e599334e8",
                  "versionType": "git"
                },
                {
                  "lessThan": "69136304fd144144a4828c7b7b149d0f80321ba4",
                  "status": "affected",
                  "version": "ef8d563f184e1112651f2cbde383d43e599334e8",
                  "versionType": "git"
                },
                {
                  "lessThan": "0a4ed2d97cb6d044196cc3e726b6699222b41019",
                  "status": "affected",
                  "version": "ef8d563f184e1112651f2cbde383d43e599334e8",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "fs/f2fs/file.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.8"
                },
                {
                  "lessThan": "5.8",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.219",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.161",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.93",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.33",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.219",
                      "versionStartIncluding": "5.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.161",
                      "versionStartIncluding": "5.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.93",
                      "versionStartIncluding": "5.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.33",
                      "versionStartIncluding": "5.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.4",
                      "versionStartIncluding": "5.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "5.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: compress: fix to cover {reserve,release}_compress_blocks() w/ cp_rwsem lock\n\nIt needs to cover {reserve,release}_compress_blocks() w/ cp_rwsem lock\nto avoid racing with checkpoint, otherwise, filesystem metadata including\nblkaddr in dnode, inode fields and .total_valid_block_count may be\ncorrupted after SPO case."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The vulnerability is reached only through the `F2FS_IOC_RELEASE_COMPRESS_BLOCKS` / `F2FS_IOC_RESERVE_COMPRESS_BLOCKS` ioctls issued on a local file descriptor of a mounted f2fs volume. There is no remote or network-facing path into `f2fs_{release,reserve}_compress_blocks()`.\nAC:L - The attacker drives both sides of the race \u2014 one thread loops the compress-block ioctls while another loops unprivileged `syncfs()`, which calls `f2fs_sync_fs(sb, 1)` \u2192 `f2fs_issue_checkpoint()`, so the racing checkpoint is attacker-scheduled rather than incidental. Once won, the inconsistent metadata is written to persistent storage and stays there, and f2fs compression is broadly deployed (Android GKI enables `CONFIG_F2FS_FS_COMPRESSION`), so no condition outside the attacker\u0027s influence is needed to reach the corrupt state.\nPR:L - Both ioctls carry no `capable()` or `CAP_SYS_ADMIN` check \u2014 unlike the adjacent `F2FS_IOC_RESIZE_FS`/`GARBAGE_COLLECT` handlers \u2014 and setting `FS_COMPR_FL` requires only `inode_owner_or_capable`. Any unprivileged local user with a file on a rw-mounted compression-enabled f2fs volume can create a compressed file and invoke them.\nUI:N - The attacker operates entirely on a file it creates and owns on an already-mounted filesystem, in a self-contained two-thread loop. No action by any other user or administrator is required.\nS:U - The corruption is confined to the f2fs filesystem metadata managed by the same kernel security authority that hosts the vulnerable code. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The persisted mismatch between inode compress accounting (`i_blocks`, `i_compr_blocks`, `FI_COMPRESS_RELEASED`) and the dnode blkaddr layout means a compressed cluster can be decompressed using a block count that no longer matches its real extent, surfacing content of blocks outside the file \u2014 a cross-file disclosure on a shared volume, which is why the fs is flagged `SBI_NEED_FSCK` rather than merely losing space.\nI:H - An unprivileged user achieves persistent, unauthorized corruption of shared on-disk filesystem metadata \u2014 dnode block addresses, inode `i_blocks`/`i_compr_blocks`, and the volume-global `total_valid_block_count` \u2014 affecting the entire filesystem and not just the attacker\u0027s own file, repairable only by fsck.\nA:H - After the unclean mount, `f2fs_sanity_check_ckpt()` rejects the volume with \"Wrong valid_user_blocks\" (`-EFSCORRUPTED`), rendering an f2fs root or `/data` unmountable and the device unbootable; `dec_valid_block_count()`\u0027s `f2fs_bug_on(sbi, sbi-\u003etotal_valid_block_count \u003c count)` also yields a `BUG_ON` kernel panic under `CONFIG_F2FS_CHECK_FS`, with `SBI_NEED_FSCK`/forced read-only otherwise."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:29:52.924Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/a6e1f7744e9b84f86a629a76024bba8468aa153b"
            },
            {
              "url": "https://git.kernel.org/stable/c/b5bac43875aa27ec032dbbb86173baae6dce6182"
            },
            {
              "url": "https://git.kernel.org/stable/c/5d47d63883735718825ca2efc4fca6915469774f"
            },
            {
              "url": "https://git.kernel.org/stable/c/329edb7c9e3b6ca27e6ca67ab1cdda1740fb3a2b"
            },
            {
              "url": "https://git.kernel.org/stable/c/69136304fd144144a4828c7b7b149d0f80321ba4"
            },
            {
              "url": "https://git.kernel.org/stable/c/0a4ed2d97cb6d044196cc3e726b6699222b41019"
            }
          ],
          "title": "f2fs: compress: fix to cover {reserve,release}_compress_blocks() w/ cp_rwsem lock",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-34027",
        "datePublished": "2024-06-24T13:56:49.389Z",
        "dateReserved": "2024-06-24T13:54:11.051Z",
        "dateUpdated": "2026-08-05T11:29:52.924Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-38384 (GCVE-0-2024-38384)

    Vulnerability from cvelistv5 – Published: 2024-06-24 13:50 – Updated: 2026-08-05 11:32
    VLAI
    Title
    blk-cgroup: fix list corruption from reorder of WRITE ->lqueued
    Summary
    In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption from reorder of WRITE ->lqueued __blkcg_rstat_flush() can be run anytime, especially when blk_cgroup_bio_start is being executed. If WRITE of `->lqueued` is re-ordered with READ of 'bisc->lnode.next' in the loop of __blkcg_rstat_flush(), `next_bisc` can be assigned with one stat instance being added in blk_cgroup_bio_start(), then the local list in __blkcg_rstat_flush() could be corrupted. Fix the issue by adding one barrier.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-25 13:27 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 3b8cc6298724021da845f2f9fd7dd4b6829a6817 , < 714e59b5456e4d6e4295a9968c564abe193f461c (git)
    Affected: 3b8cc6298724021da845f2f9fd7dd4b6829a6817 , < 785298ab6b802afa75089239266b6bbea590809c (git)
    Affected: 3b8cc6298724021da845f2f9fd7dd4b6829a6817 , < d0aac2363549e12cc79b8e285f13d5a9f42fd08e (git)
    Create a notification for this product.
    Linux Linux Affected: 6.2
    Unaffected: 0 , < 6.2 (semver)
    Unaffected: 6.6.33 , ≤ 6.6.* (semver)
    Unaffected: 6.9.4 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 3b8cc6298724 , < 714e59b5456e (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 3b8cc6298724 , < 785298ab6b80 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 3b8cc6298724 , < d0aac2363549 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 6.2
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 6.2 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.33 , ≤ 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9.4 , ≤ 6.10 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.10-rc1
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "714e59b5456e",
                    "status": "affected",
                    "version": "3b8cc6298724",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "785298ab6b80",
                    "status": "affected",
                    "version": "3b8cc6298724",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "d0aac2363549",
                    "status": "affected",
                    "version": "3b8cc6298724",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.2"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.2",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.7",
                    "status": "unaffected",
                    "version": "6.6.33",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.10",
                    "status": "unaffected",
                    "version": "6.9.4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.10-rc1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.4,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-38384",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-25T13:27:38.979262Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-25T13:37:27.542Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T04:04:25.142Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/714e59b5456e4d6e4295a9968c564abe193f461c"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/785298ab6b802afa75089239266b6bbea590809c"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/d0aac2363549e12cc79b8e285f13d5a9f42fd08e"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "block/blk-cgroup.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "714e59b5456e4d6e4295a9968c564abe193f461c",
                  "status": "affected",
                  "version": "3b8cc6298724021da845f2f9fd7dd4b6829a6817",
                  "versionType": "git"
                },
                {
                  "lessThan": "785298ab6b802afa75089239266b6bbea590809c",
                  "status": "affected",
                  "version": "3b8cc6298724021da845f2f9fd7dd4b6829a6817",
                  "versionType": "git"
                },
                {
                  "lessThan": "d0aac2363549e12cc79b8e285f13d5a9f42fd08e",
                  "status": "affected",
                  "version": "3b8cc6298724021da845f2f9fd7dd4b6829a6817",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "block/blk-cgroup.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.2"
                },
                {
                  "lessThan": "6.2",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.33",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.33",
                      "versionStartIncluding": "6.2",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.4",
                      "versionStartIncluding": "6.2",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "6.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: fix list corruption from reorder of WRITE -\u003elqueued\n\n__blkcg_rstat_flush() can be run anytime, especially when blk_cgroup_bio_start\nis being executed.\n\nIf WRITE of `-\u003elqueued` is re-ordered with READ of \u0027bisc-\u003elnode.next\u0027 in\nthe loop of __blkcg_rstat_flush(), `next_bisc` can be assigned with one\nstat instance being added in blk_cgroup_bio_start(), then the local\nlist in __blkcg_rstat_flush() could be corrupted.\n\nFix the issue by adding one barrier."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The vulnerable code is reached through local block-I/O submission (`submit_bio_noacct_nocheck` \u2192 `blk_cgroup_bio_start`) and local cgroupfs reads of `io.stat`; there is no network-facing path into blk-cgroup stat accounting.\nAC:L - The attacker drives both sides of the race \u2014 continuous bio submission on multiple CPUs plus a tight loop reading `io.stat` (or removing cgroups) to force `blkcg_rstat_flush` \u2014 and can retry indefinitely with no cost until the reorder window is hit on any weakly-ordered CPU.\nPR:L - No capability check exists on either code path; any unprivileged local user performing ordinary file I/O inside a non-root cgroup-v2 blkcg (the default for every systemd user session and every container) can reach both `blk_cgroup_bio_start()` and, via their delegated subtree\u0027s `io.stat`, the flush side.\nUI:N - The attacker triggers everything from its own processes \u2014 I/O submission and stat flushing \u2014 with no action required from any other user or administrator.\nS:U - The corruption is confined to kernel block-cgroup structures within the same security authority; no VM, IOMMU, or hypervisor boundary is crossed.\nC:H - Corruption of the lockless list defeats the `__blkg_release()` flush that guarantees no `blkg_iostat_set` is queued before `free_percpu(blkg-\u003eiostat_cpu)`, leaving the list pointing into freed per-CPU memory that is then dereferenced (`bisc-\u003eblkg`, `blkg-\u003eparent`) \u2014 a use-after-free read that can be leveraged for kernel memory disclosure.\nI:H - The same stale-pointer condition makes `blkcg_iostat_update()` write through a `blkg` pointer read out of freed memory, giving an attacker-influenceable write primitive; the llist `next` pointers themselves are also corrupted with attacker-timed values.\nA:H - Re-adding a node that is still linked creates a cycle in the lockless list, so the next `__blkcg_rstat_flush()` loops forever while holding the `blkg_stat_lock` raw spinlock with interrupts disabled under `cgroup_rstat_lock` \u2014 a hard lockup / kernel panic that wedges the whole system."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:32:34.192Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/714e59b5456e4d6e4295a9968c564abe193f461c"
            },
            {
              "url": "https://git.kernel.org/stable/c/785298ab6b802afa75089239266b6bbea590809c"
            },
            {
              "url": "https://git.kernel.org/stable/c/d0aac2363549e12cc79b8e285f13d5a9f42fd08e"
            }
          ],
          "title": "blk-cgroup: fix list corruption from reorder of WRITE -\u003elqueued",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-38384",
        "datePublished": "2024-06-24T13:50:51.033Z",
        "dateReserved": "2024-06-21T11:16:40.612Z",
        "dateUpdated": "2026-08-05T11:32:34.192Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-39277 (GCVE-0-2024-39277)

    Vulnerability from cvelistv5 – Published: 2024-06-21 11:15 – Updated: 2026-05-11 20:20
    VLAI
    Title
    dma-mapping: benchmark: handle NUMA_NO_NODE correctly
    Summary
    In the Linux kernel, the following vulnerability has been resolved: dma-mapping: benchmark: handle NUMA_NO_NODE correctly cpumask_of_node() can be called for NUMA_NO_NODE inside do_map_benchmark() resulting in the following sanitizer report: UBSAN: array-index-out-of-bounds in ./arch/x86/include/asm/topology.h:72:28 index -1 is out of range for type 'cpumask [64][1]' CPU: 1 PID: 990 Comm: dma_map_benchma Not tainted 6.9.0-rc6 #29 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) Call Trace: <TASK> dump_stack_lvl (lib/dump_stack.c:117) ubsan_epilogue (lib/ubsan.c:232) __ubsan_handle_out_of_bounds (lib/ubsan.c:429) cpumask_of_node (arch/x86/include/asm/topology.h:72) [inline] do_map_benchmark (kernel/dma/map_benchmark.c:104) map_benchmark_ioctl (kernel/dma/map_benchmark.c:246) full_proxy_unlocked_ioctl (fs/debugfs/file.c:333) __x64_sys_ioctl (fs/ioctl.c:890) do_syscall_64 (arch/x86/entry/common.c:83) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) Use cpumask_of_node() in place when binding a kernel thread to a cpuset of a particular node. Note that the provided node id is checked inside map_benchmark_ioctl(). It's just a NUMA_NO_NODE case which is not handled properly later. Found by Linux Verification Center (linuxtesting.org).
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-20 03:55 UTC
    CWE
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 65789daa8087e125927230ccb7e1eab13999b0cf , < b41b0018e8ca06e985e87220a618ec633988fd13 (git)
    Affected: 65789daa8087e125927230ccb7e1eab13999b0cf , < 8e1ba9df9a35e8dc64f657a64e523c79ba01e464 (git)
    Affected: 65789daa8087e125927230ccb7e1eab13999b0cf , < 5a91116b003175302f2e6ad94b76fb9b5a141a41 (git)
    Affected: 65789daa8087e125927230ccb7e1eab13999b0cf , < 50ee21bfc005e69f183d6b4b454e33f0c2571e1f (git)
    Affected: 65789daa8087e125927230ccb7e1eab13999b0cf , < e64746e74f717961250a155e14c156616fcd981f (git)
    Create a notification for this product.
    Linux Linux Affected: 5.11
    Unaffected: 0 , < 5.11 (semver)
    Unaffected: 5.15.161 , ≤ 5.15.* (semver)
    Unaffected: 6.1.93 , ≤ 6.1.* (semver)
    Unaffected: 6.6.33 , ≤ 6.6.* (semver)
    Unaffected: 6.9.4 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 5.11
        cpe:2.3:o:linux:linux_kernel:5.11:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 65789daa8087 , < b41b0018e8ca (git)
    Affected: 65789daa8087 , < 8e1ba9df9a35 (git)
    Affected: 65789daa8087 , < 5a91116b0031 (git)
    Affected: 65789daa8087 , < 50ee21bfc005 (git)
    Affected: 65789daa8087 , < e64746e74f71 (git)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:5.11:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.11"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "b41b0018e8ca",
                    "status": "affected",
                    "version": "65789daa8087",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "8e1ba9df9a35",
                    "status": "affected",
                    "version": "65789daa8087",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5a91116b0031",
                    "status": "affected",
                    "version": "65789daa8087",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "50ee21bfc005",
                    "status": "affected",
                    "version": "65789daa8087",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "e64746e74f71",
                    "status": "affected",
                    "version": "65789daa8087",
                    "versionType": "git"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-39277",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-20T03:55:13.483536Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-125",
                    "description": "CWE-125 Out-of-bounds Read",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-20T13:31:39.441Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T04:19:20.704Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/b41b0018e8ca06e985e87220a618ec633988fd13"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/8e1ba9df9a35e8dc64f657a64e523c79ba01e464"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/5a91116b003175302f2e6ad94b76fb9b5a141a41"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/50ee21bfc005e69f183d6b4b454e33f0c2571e1f"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/e64746e74f717961250a155e14c156616fcd981f"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "kernel/dma/map_benchmark.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "b41b0018e8ca06e985e87220a618ec633988fd13",
                  "status": "affected",
                  "version": "65789daa8087e125927230ccb7e1eab13999b0cf",
                  "versionType": "git"
                },
                {
                  "lessThan": "8e1ba9df9a35e8dc64f657a64e523c79ba01e464",
                  "status": "affected",
                  "version": "65789daa8087e125927230ccb7e1eab13999b0cf",
                  "versionType": "git"
                },
                {
                  "lessThan": "5a91116b003175302f2e6ad94b76fb9b5a141a41",
                  "status": "affected",
                  "version": "65789daa8087e125927230ccb7e1eab13999b0cf",
                  "versionType": "git"
                },
                {
                  "lessThan": "50ee21bfc005e69f183d6b4b454e33f0c2571e1f",
                  "status": "affected",
                  "version": "65789daa8087e125927230ccb7e1eab13999b0cf",
                  "versionType": "git"
                },
                {
                  "lessThan": "e64746e74f717961250a155e14c156616fcd981f",
                  "status": "affected",
                  "version": "65789daa8087e125927230ccb7e1eab13999b0cf",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "kernel/dma/map_benchmark.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.11"
                },
                {
                  "lessThan": "5.11",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.161",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.93",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.33",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.161",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.93",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.33",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.4",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndma-mapping: benchmark: handle NUMA_NO_NODE correctly\n\ncpumask_of_node() can be called for NUMA_NO_NODE inside do_map_benchmark()\nresulting in the following sanitizer report:\n\nUBSAN: array-index-out-of-bounds in ./arch/x86/include/asm/topology.h:72:28\nindex -1 is out of range for type \u0027cpumask [64][1]\u0027\nCPU: 1 PID: 990 Comm: dma_map_benchma Not tainted 6.9.0-rc6 #29\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996)\nCall Trace:\n \u003cTASK\u003e\ndump_stack_lvl (lib/dump_stack.c:117)\nubsan_epilogue (lib/ubsan.c:232)\n__ubsan_handle_out_of_bounds (lib/ubsan.c:429)\ncpumask_of_node (arch/x86/include/asm/topology.h:72) [inline]\ndo_map_benchmark (kernel/dma/map_benchmark.c:104)\nmap_benchmark_ioctl (kernel/dma/map_benchmark.c:246)\nfull_proxy_unlocked_ioctl (fs/debugfs/file.c:333)\n__x64_sys_ioctl (fs/ioctl.c:890)\ndo_syscall_64 (arch/x86/entry/common.c:83)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n\nUse cpumask_of_node() in place when binding a kernel thread to a cpuset\nof a particular node.\n\nNote that the provided node id is checked inside map_benchmark_ioctl().\nIt\u0027s just a NUMA_NO_NODE case which is not handled properly later.\n\nFound by Linux Verification Center (linuxtesting.org)."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T20:20:48.721Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/b41b0018e8ca06e985e87220a618ec633988fd13"
            },
            {
              "url": "https://git.kernel.org/stable/c/8e1ba9df9a35e8dc64f657a64e523c79ba01e464"
            },
            {
              "url": "https://git.kernel.org/stable/c/5a91116b003175302f2e6ad94b76fb9b5a141a41"
            },
            {
              "url": "https://git.kernel.org/stable/c/50ee21bfc005e69f183d6b4b454e33f0c2571e1f"
            },
            {
              "url": "https://git.kernel.org/stable/c/e64746e74f717961250a155e14c156616fcd981f"
            }
          ],
          "title": "dma-mapping: benchmark: handle NUMA_NO_NODE correctly",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-39277",
        "datePublished": "2024-06-21T11:15:13.559Z",
        "dateReserved": "2024-06-21T10:12:11.489Z",
        "dateUpdated": "2026-05-11T20:20:48.721Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-38623 (GCVE-0-2024-38623)

    Vulnerability from cvelistv5 – Published: 2024-06-21 10:18 – Updated: 2026-08-05 11:33
    VLAI
    Title
    fs/ntfs3: Use variable length array instead of fixed size
    Summary
    In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Use variable length array instead of fixed size Should fix smatch warning: ntfs_set_label() error: __builtin_memcpy() 'uni->name' too small (20 vs 256)
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-25 14:54 UTC
    CWE
    • CWE-129 - Improper Validation of Array Index
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e , < a2de301d90b782ac5d7a5fe32995caaee9ab3a0f (git)
    Affected: 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e , < 3839a9b19a4b70eff6b6ad70446f639f7fd5a3d7 (git)
    Affected: 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e , < 1fe1c9dc21ee52920629d2d9b9bd84358931a8d1 (git)
    Affected: 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e , < cceef44b34819c24bb6ed70dce5b524bd3e368d1 (git)
    Affected: 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e , < 1997cdc3e727526aa5d84b32f7cbb3f56459b7ef (git)
    Create a notification for this product.
    Linux Linux Affected: 5.15
    Unaffected: 0 , < 5.15 (semver)
    Unaffected: 5.15.161 , ≤ 5.15.* (semver)
    Unaffected: 6.1.93 , ≤ 6.1.* (semver)
    Unaffected: 6.6.33 , ≤ 6.6.* (semver)
    Unaffected: 6.9.4 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 4534a70b7056 , < a2de301d90b7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 4534a70b7056 , < 3839a9b19a4b (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 4534a70b7056 , < 1fe1c9dc21ee (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 4534a70b7056 , < cceef44b3481 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 4534a70b7056 , < 1997cdc3e727 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 5.15
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 5.15 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.15.161 , ≤ 5.16 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.1.93 , ≤ 6.2 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.33 , ≤ 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9.4 , ≤ 6.10 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.10-rc1
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "a2de301d90b7",
                    "status": "affected",
                    "version": "4534a70b7056",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3839a9b19a4b",
                    "status": "affected",
                    "version": "4534a70b7056",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "1fe1c9dc21ee",
                    "status": "affected",
                    "version": "4534a70b7056",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "cceef44b3481",
                    "status": "affected",
                    "version": "4534a70b7056",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "1997cdc3e727",
                    "status": "affected",
                    "version": "4534a70b7056",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.15"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.15",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.16",
                    "status": "unaffected",
                    "version": "5.15.161",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.2",
                    "status": "unaffected",
                    "version": "6.1.93",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.7",
                    "status": "unaffected",
                    "version": "6.6.33",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.10",
                    "status": "unaffected",
                    "version": "6.9.4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.10-rc1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-38623",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-25T14:54:31.559522Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-129",
                    "description": "CWE-129 Improper Validation of Array Index",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-25T15:08:32.014Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T04:12:25.994Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/a2de301d90b782ac5d7a5fe32995caaee9ab3a0f"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/3839a9b19a4b70eff6b6ad70446f639f7fd5a3d7"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/1fe1c9dc21ee52920629d2d9b9bd84358931a8d1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/cceef44b34819c24bb6ed70dce5b524bd3e368d1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/1997cdc3e727526aa5d84b32f7cbb3f56459b7ef"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "fs/ntfs3/ntfs.h"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "a2de301d90b782ac5d7a5fe32995caaee9ab3a0f",
                  "status": "affected",
                  "version": "4534a70b7056fd4b9a1c6db5a4ce3c98546b291e",
                  "versionType": "git"
                },
                {
                  "lessThan": "3839a9b19a4b70eff6b6ad70446f639f7fd5a3d7",
                  "status": "affected",
                  "version": "4534a70b7056fd4b9a1c6db5a4ce3c98546b291e",
                  "versionType": "git"
                },
                {
                  "lessThan": "1fe1c9dc21ee52920629d2d9b9bd84358931a8d1",
                  "status": "affected",
                  "version": "4534a70b7056fd4b9a1c6db5a4ce3c98546b291e",
                  "versionType": "git"
                },
                {
                  "lessThan": "cceef44b34819c24bb6ed70dce5b524bd3e368d1",
                  "status": "affected",
                  "version": "4534a70b7056fd4b9a1c6db5a4ce3c98546b291e",
                  "versionType": "git"
                },
                {
                  "lessThan": "1997cdc3e727526aa5d84b32f7cbb3f56459b7ef",
                  "status": "affected",
                  "version": "4534a70b7056fd4b9a1c6db5a4ce3c98546b291e",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "fs/ntfs3/ntfs.h"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.15"
                },
                {
                  "lessThan": "5.15",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.161",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.93",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.33",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.161",
                      "versionStartIncluding": "5.15",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.93",
                      "versionStartIncluding": "5.15",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.33",
                      "versionStartIncluding": "5.15",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.4",
                      "versionStartIncluding": "5.15",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "5.15",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Use variable length array instead of fixed size\n\nShould fix smatch warning:\n\tntfs_set_label() error: __builtin_memcpy() \u0027uni-\u003ename\u0027 too small (20 vs 256)"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The affected code is the ntfs3 local filesystem name/label handling, reached through ordinary VFS syscalls (open/creat/link/rename/lookup) on a mounted volume or a write to /proc/fs/ntfs3/\u003cdev\u003e/label. No network protocol handling is involved.\nAC:L - Triggering is fully deterministic \u2014 the attacker simply supplies a name or label longer than 10 UTF-16 units, and the copy length is directly attacker-controlled. There is no race, no memory-layout dependency, and no condition outside the attacker\u0027s control.\nPR:L - While the ntfs_set_label() path is root-gated, the identical mis-sized cpu_str accesses in fill_name_de(), ntfs_lookup(), ntfs_d_hash() and ntfs_d_compare() are reached by any unprivileged user creating, renaming, linking or merely looking up a long file name on an already-mounted ntfs3 volume.\nUI:N - No victim action is required once an ntfs3 volume is mounted, which is the normal state on desktops, kiosks, Android and media devices with USB/NTFS storage; the attacker acts entirely on their own.\nS:U - The corruption stays within kernel memory under the same security authority; there is no VM, IOMMU or sandbox boundary crossed.\nC:H - Up to 256 bytes (label path) and 510 bytes (name path) are read out of a 20-byte-declared array, an out-of-bounds read far beyond a few bounded bytes that can disclose adjacent kernel heap contents into on-disk name/label attributes readable by the attacker.\nI:H - The same paths write up to 510 bytes through the 20-byte-declared name member with attacker-controlled length and content, an out-of-bounds write that is the classic primitive for adjacent-object corruption and control-flow hijack.\nA:H - Out-of-declared-bounds access of this size corrupts or over-reads adjacent kernel heap state and trips CONFIG_FORTIFY_SOURCE field-spanning detection, resulting in kernel warnings, oops or panic (fatal with panic_on_warn)."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:33:14.587Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/a2de301d90b782ac5d7a5fe32995caaee9ab3a0f"
            },
            {
              "url": "https://git.kernel.org/stable/c/3839a9b19a4b70eff6b6ad70446f639f7fd5a3d7"
            },
            {
              "url": "https://git.kernel.org/stable/c/1fe1c9dc21ee52920629d2d9b9bd84358931a8d1"
            },
            {
              "url": "https://git.kernel.org/stable/c/cceef44b34819c24bb6ed70dce5b524bd3e368d1"
            },
            {
              "url": "https://git.kernel.org/stable/c/1997cdc3e727526aa5d84b32f7cbb3f56459b7ef"
            }
          ],
          "title": "fs/ntfs3: Use variable length array instead of fixed size",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-38623",
        "datePublished": "2024-06-21T10:18:16.291Z",
        "dateReserved": "2024-06-18T19:36:34.945Z",
        "dateUpdated": "2026-08-05T11:33:14.587Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-52883 (GCVE-0-2023-52883)

    Vulnerability from cvelistv5 – Published: 2024-06-20 11:54 – Updated: 2026-05-11 19:34
    VLAI
    Title
    drm/amdgpu: Fix possible null pointer dereference
    Summary
    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix possible null pointer dereference abo->tbo.resource may be NULL in amdgpu_vm_bo_update.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-20 18:49 UTC
    CWE
    • CWE-476 - NULL Pointer Dereference
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 1802537820389183dfcd814e0f6a60d1496a75ef , < fefac8c4686fd81fde6830c6dae32f9001d2ac28 (git)
    Affected: 1802537820389183dfcd814e0f6a60d1496a75ef , < 51b79f33817544e3b4df838d86e8e8e4388ff684 (git)
    Create a notification for this product.
    Linux Linux Affected: 6.4
    Unaffected: 0 , < 6.4 (semver)
    Unaffected: 6.5.9 , ≤ 6.5.* (semver)
    Unaffected: 6.6 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 180253782038 , < fefac8c4686f (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 180253782038 , < 51b79f338175 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 6.4
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 6.4 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.5.9 , ≤ 6.6 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "fefac8c4686f",
                    "status": "affected",
                    "version": "180253782038",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "51b79f338175",
                    "status": "affected",
                    "version": "180253782038",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.4"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.4",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.6",
                    "status": "unaffected",
                    "version": "6.5.9",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.6"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-52883",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-20T18:49:26.969492Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-476",
                    "description": "CWE-476 NULL Pointer Dereference",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-20T18:57:34.790Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T23:18:41.353Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/fefac8c4686fd81fde6830c6dae32f9001d2ac28"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/51b79f33817544e3b4df838d86e8e8e4388ff684"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "fefac8c4686fd81fde6830c6dae32f9001d2ac28",
                  "status": "affected",
                  "version": "1802537820389183dfcd814e0f6a60d1496a75ef",
                  "versionType": "git"
                },
                {
                  "lessThan": "51b79f33817544e3b4df838d86e8e8e4388ff684",
                  "status": "affected",
                  "version": "1802537820389183dfcd814e0f6a60d1496a75ef",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.4"
                },
                {
                  "lessThan": "6.4",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.5.*",
                  "status": "unaffected",
                  "version": "6.5.9",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.6",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.5.9",
                      "versionStartIncluding": "6.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6",
                      "versionStartIncluding": "6.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix possible null pointer dereference\n\nabo-\u003etbo.resource may be NULL in amdgpu_vm_bo_update."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T19:34:52.376Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/fefac8c4686fd81fde6830c6dae32f9001d2ac28"
            },
            {
              "url": "https://git.kernel.org/stable/c/51b79f33817544e3b4df838d86e8e8e4388ff684"
            }
          ],
          "title": "drm/amdgpu: Fix possible null pointer dereference",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2023-52883",
        "datePublished": "2024-06-20T11:54:26.424Z",
        "dateReserved": "2024-05-21T15:35:00.782Z",
        "dateUpdated": "2026-05-11T19:34:52.376Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2022-48754 (GCVE-0-2022-48754)

    Vulnerability from cvelistv5 – Published: 2024-06-20 11:13 – Updated: 2026-08-05 08:52
    VLAI
    Title
    phylib: fix potential use-after-free
    Summary
    In the Linux kernel, the following vulnerability has been resolved: phylib: fix potential use-after-free Commit bafbdd527d56 ("phylib: Add device reset GPIO support") added call to phy_device_reset(phydev) after the put_device() call in phy_detach(). The comment before the put_device() call says that the phydev might go away with put_device(). Fix potential use-after-free by calling phy_device_reset() before put_device().
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-25 15:12 UTC
    CWE
    Impacted products
    Vendor Product Version
    Linux Linux Affected: bafbdd527d569c8200521f2f7579f65a044271be , < 67d271760b037ce0806d687ee6057edc8afd4205 (git)
    Affected: bafbdd527d569c8200521f2f7579f65a044271be , < f39027cbada43b33566c312e6be3db654ca3ad17 (git)
    Affected: bafbdd527d569c8200521f2f7579f65a044271be , < bd024e36f68174b1793906c39ca16cee0c9295c2 (git)
    Affected: bafbdd527d569c8200521f2f7579f65a044271be , < aefaccd19379d6c4620269a162bfb88ff687f289 (git)
    Affected: bafbdd527d569c8200521f2f7579f65a044271be , < cb2fab10fc5e7a3aa1bb0a68a3abdcf3e37852af (git)
    Affected: bafbdd527d569c8200521f2f7579f65a044271be , < cbda1b16687580d5beee38273f6241ae3725960c (git)
    Create a notification for this product.
    Linux Linux Affected: 4.16
    Unaffected: 0 , < 4.16 (semver)
    Unaffected: 4.19.228 , ≤ 4.19.* (semver)
    Unaffected: 5.4.176 , ≤ 5.4.* (semver)
    Unaffected: 5.10.96 , ≤ 5.10.* (semver)
    Unaffected: 5.15.19 , ≤ 5.15.* (semver)
    Unaffected: 5.16.5 , ≤ 5.16.* (semver)
    Unaffected: 5.17 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: bafbdd527d56 , < 67d271760b03 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: bafbdd527d56 , < f39027cbada4 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: bafbdd527d56 , < bd024e36f681 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: bafbdd527d56 , < aefaccd19379 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: bafbdd527d56 , < cb2fab10fc5e (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: bafbdd527d56 , < cbda1b166875 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 4.16
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 4.16 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 4.19.228 , ≤ 4.20 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.4.176 , ≤ 5.5 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.10.96 , ≤ 5.11 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.15.19 , ≤ 5.16 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.16.5 , ≤ 5.17 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.17
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "67d271760b03",
                    "status": "affected",
                    "version": "bafbdd527d56",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "f39027cbada4",
                    "status": "affected",
                    "version": "bafbdd527d56",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "bd024e36f681",
                    "status": "affected",
                    "version": "bafbdd527d56",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "aefaccd19379",
                    "status": "affected",
                    "version": "bafbdd527d56",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "cb2fab10fc5e",
                    "status": "affected",
                    "version": "bafbdd527d56",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "cbda1b166875",
                    "status": "affected",
                    "version": "bafbdd527d56",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.16"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "4.16",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "4.20",
                    "status": "unaffected",
                    "version": "4.19.228",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.5",
                    "status": "unaffected",
                    "version": "5.4.176",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.11",
                    "status": "unaffected",
                    "version": "5.10.96",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.16",
                    "status": "unaffected",
                    "version": "5.15.19",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.17",
                    "status": "unaffected",
                    "version": "5.16.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "5.17"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.4,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-48754",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-25T15:12:03.815461Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-25T15:26:05.300Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T15:25:01.127Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/67d271760b037ce0806d687ee6057edc8afd4205"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/f39027cbada43b33566c312e6be3db654ca3ad17"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/bd024e36f68174b1793906c39ca16cee0c9295c2"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/aefaccd19379d6c4620269a162bfb88ff687f289"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/cb2fab10fc5e7a3aa1bb0a68a3abdcf3e37852af"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/cbda1b16687580d5beee38273f6241ae3725960c"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/net/phy/phy_device.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "67d271760b037ce0806d687ee6057edc8afd4205",
                  "status": "affected",
                  "version": "bafbdd527d569c8200521f2f7579f65a044271be",
                  "versionType": "git"
                },
                {
                  "lessThan": "f39027cbada43b33566c312e6be3db654ca3ad17",
                  "status": "affected",
                  "version": "bafbdd527d569c8200521f2f7579f65a044271be",
                  "versionType": "git"
                },
                {
                  "lessThan": "bd024e36f68174b1793906c39ca16cee0c9295c2",
                  "status": "affected",
                  "version": "bafbdd527d569c8200521f2f7579f65a044271be",
                  "versionType": "git"
                },
                {
                  "lessThan": "aefaccd19379d6c4620269a162bfb88ff687f289",
                  "status": "affected",
                  "version": "bafbdd527d569c8200521f2f7579f65a044271be",
                  "versionType": "git"
                },
                {
                  "lessThan": "cb2fab10fc5e7a3aa1bb0a68a3abdcf3e37852af",
                  "status": "affected",
                  "version": "bafbdd527d569c8200521f2f7579f65a044271be",
                  "versionType": "git"
                },
                {
                  "lessThan": "cbda1b16687580d5beee38273f6241ae3725960c",
                  "status": "affected",
                  "version": "bafbdd527d569c8200521f2f7579f65a044271be",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/net/phy/phy_device.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.16"
                },
                {
                  "lessThan": "4.16",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "4.19.*",
                  "status": "unaffected",
                  "version": "4.19.228",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.176",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.96",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.19",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.16.*",
                  "status": "unaffected",
                  "version": "5.16.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "5.17",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.19.228",
                      "versionStartIncluding": "4.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.176",
                      "versionStartIncluding": "4.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.96",
                      "versionStartIncluding": "4.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.19",
                      "versionStartIncluding": "4.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.16.5",
                      "versionStartIncluding": "4.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.17",
                      "versionStartIncluding": "4.16",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nphylib: fix potential use-after-free\n\nCommit bafbdd527d56 (\"phylib: Add device reset GPIO support\") added call\nto phy_device_reset(phydev) after the put_device() call in phy_detach().\n\nThe comment before the put_device() call says that the phydev might go\naway with put_device().\n\nFix potential use-after-free by calling phy_device_reset() before\nput_device()."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The vulnerable path is phy_detach(), reached via local netdev admin (ndo_stop/ifdown \u2192 phy_disconnect) or local driver teardown/phylink/SFP paths, not via remotely received packets or protocols.\nAC:L - This is a use-after-free on a code path the attacker can invoke directly; when put_device drops the final reference (the case the surrounding comment and attach refcounting were written for), phy_device_reset() reliably touches freed phydev memory with no additional chance conditions.\nPR:L - Triggering requires CAP_NET_ADMIN to bring down or otherwise detach a PHY-backed interface, which is available to an unprivileged user via user namespaces/containers that have been given such a netdev, not only full init-namespace root.\nUI:N - No separate victim action is required; the attacker who can perform the netdev/driver operation triggers the bug themselves.\nS:U - Impact stays within the local kernel/host authority; this is a standard kernel UAF privilege-escalation class issue, not a VM/sandbox/IOMMU boundary escape.\nC:H - Use-after-free of struct phy_device lets an attacker reclaim and control the object contents, enabling arbitrary kernel read primitives via the subsequent reset_gpio/reset_ctrl use.\nI:H - The same UAF enables heap spraying and corruption of the freed phy_device so that mdio_device_reset()\u0027s gpiod/reset_control calls become arbitrary write/control-flow primitives.\nA:H - Use-after-free of a kernel device object can cause kernel oops/panic even without full exploitation, so availability impact is high."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T08:52:08.868Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/67d271760b037ce0806d687ee6057edc8afd4205"
            },
            {
              "url": "https://git.kernel.org/stable/c/f39027cbada43b33566c312e6be3db654ca3ad17"
            },
            {
              "url": "https://git.kernel.org/stable/c/bd024e36f68174b1793906c39ca16cee0c9295c2"
            },
            {
              "url": "https://git.kernel.org/stable/c/aefaccd19379d6c4620269a162bfb88ff687f289"
            },
            {
              "url": "https://git.kernel.org/stable/c/cb2fab10fc5e7a3aa1bb0a68a3abdcf3e37852af"
            },
            {
              "url": "https://git.kernel.org/stable/c/cbda1b16687580d5beee38273f6241ae3725960c"
            }
          ],
          "title": "phylib: fix potential use-after-free",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2022-48754",
        "datePublished": "2024-06-20T11:13:34.561Z",
        "dateReserved": "2024-06-20T11:09:39.057Z",
        "dateUpdated": "2026-08-05T08:52:08.868Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2022-48748 (GCVE-0-2022-48748)

    Vulnerability from cvelistv5 – Published: 2024-06-20 11:13 – Updated: 2026-05-11 18:46
    VLAI
    Title
    net: bridge: vlan: fix memory leak in __allowed_ingress
    Summary
    In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state, if vlan snooping and stats are disabled, untagged or priority-tagged ingress frame will go to check pvid state. If the port state is forwarding and the pvid state is not learning/forwarding, untagged or priority-tagged frame will be dropped but skb memory is not freed. Should free skb when __allowed_ingress returns false.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-26 14:37 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    Linux Linux Affected: a580c76d534c7360ba68042b19cb255e8420e987 , < 446ff1fc37c74093e81db40811a07b5a19f1d797 (git)
    Affected: a580c76d534c7360ba68042b19cb255e8420e987 , < c5e216e880fa6f2cd9d4a6541269377657163098 (git)
    Affected: a580c76d534c7360ba68042b19cb255e8420e987 , < 14be8d448fca6fe7b2a413831eedd55aef6c6511 (git)
    Affected: a580c76d534c7360ba68042b19cb255e8420e987 , < fd20d9738395cf8e27d0a17eba34169699fccdff (git)
    Create a notification for this product.
    Linux Linux Affected: 5.6
    Unaffected: 0 , < 5.6 (semver)
    Unaffected: 5.10.96 , ≤ 5.10.* (semver)
    Unaffected: 5.15.19 , ≤ 5.15.* (semver)
    Unaffected: 5.16.5 , ≤ 5.16.* (semver)
    Unaffected: 5.17 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: a580c76d534c , < 446ff1fc37c7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: a580c76d534c , < c5e216e880fa (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: a580c76d534c , < 14be8d448fca (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: a580c76d534c , < fd20d9738395 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 5.6
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 5.6 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.10.96 , ≤ 5.11 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.15.19 , ≤ 5.16 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.16.5 , ≤ 5.17 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.17
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "446ff1fc37c7",
                    "status": "affected",
                    "version": "a580c76d534c",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "c5e216e880fa",
                    "status": "affected",
                    "version": "a580c76d534c",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "14be8d448fca",
                    "status": "affected",
                    "version": "a580c76d534c",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "fd20d9738395",
                    "status": "affected",
                    "version": "a580c76d534c",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.6"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.6",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.11",
                    "status": "unaffected",
                    "version": "5.10.96",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.16",
                    "status": "unaffected",
                    "version": "5.15.19",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.17",
                    "status": "unaffected",
                    "version": "5.16.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "5.17"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-48748",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-26T14:37:10.652624Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-26T14:50:05.679Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T15:25:01.588Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/446ff1fc37c74093e81db40811a07b5a19f1d797"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/c5e216e880fa6f2cd9d4a6541269377657163098"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/14be8d448fca6fe7b2a413831eedd55aef6c6511"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/fd20d9738395cf8e27d0a17eba34169699fccdff"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/bridge/br_vlan.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "446ff1fc37c74093e81db40811a07b5a19f1d797",
                  "status": "affected",
                  "version": "a580c76d534c7360ba68042b19cb255e8420e987",
                  "versionType": "git"
                },
                {
                  "lessThan": "c5e216e880fa6f2cd9d4a6541269377657163098",
                  "status": "affected",
                  "version": "a580c76d534c7360ba68042b19cb255e8420e987",
                  "versionType": "git"
                },
                {
                  "lessThan": "14be8d448fca6fe7b2a413831eedd55aef6c6511",
                  "status": "affected",
                  "version": "a580c76d534c7360ba68042b19cb255e8420e987",
                  "versionType": "git"
                },
                {
                  "lessThan": "fd20d9738395cf8e27d0a17eba34169699fccdff",
                  "status": "affected",
                  "version": "a580c76d534c7360ba68042b19cb255e8420e987",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/bridge/br_vlan.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.6"
                },
                {
                  "lessThan": "5.6",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.96",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.19",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.16.*",
                  "status": "unaffected",
                  "version": "5.16.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "5.17",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.96",
                      "versionStartIncluding": "5.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.19",
                      "versionStartIncluding": "5.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.16.5",
                      "versionStartIncluding": "5.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.17",
                      "versionStartIncluding": "5.6",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: vlan: fix memory leak in __allowed_ingress\n\nWhen using per-vlan state, if vlan snooping and stats are disabled,\nuntagged or priority-tagged ingress frame will go to check pvid state.\nIf the port state is forwarding and the pvid state is not\nlearning/forwarding, untagged or priority-tagged frame will be dropped\nbut skb memory is not freed.\nShould free skb when __allowed_ingress returns false."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T18:46:10.125Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/446ff1fc37c74093e81db40811a07b5a19f1d797"
            },
            {
              "url": "https://git.kernel.org/stable/c/c5e216e880fa6f2cd9d4a6541269377657163098"
            },
            {
              "url": "https://git.kernel.org/stable/c/14be8d448fca6fe7b2a413831eedd55aef6c6511"
            },
            {
              "url": "https://git.kernel.org/stable/c/fd20d9738395cf8e27d0a17eba34169699fccdff"
            }
          ],
          "title": "net: bridge: vlan: fix memory leak in __allowed_ingress",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2022-48748",
        "datePublished": "2024-06-20T11:13:30.612Z",
        "dateReserved": "2024-06-20T11:09:39.055Z",
        "dateUpdated": "2026-05-11T18:46:10.125Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2022-48747 (GCVE-0-2022-48747)

    Vulnerability from cvelistv5 – Published: 2024-06-20 11:13 – Updated: 2026-05-23 15:20
    VLAI
    Title
    block: Fix wrong offset in bio_truncate()
    Summary
    In the Linux kernel, the following vulnerability has been resolved: block: Fix wrong offset in bio_truncate() bio_truncate() clears the buffer outside of last block of bdev, however current bio_truncate() is using the wrong offset of page. So it can return the uninitialized data. This happened when both of truncated/corrupted FS and userspace (via bdev) are trying to read the last of bdev.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-26 14:56 UTC
    CWE
    • CWE-908 - Use of Uninitialized Resource
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 943cd69efac437d82a7aea0659fccbcc071730de , < 6cbf4c731d7812518cd857c2cfc3da9fd120f6ae (git)
    Affected: 85a8ce62c2eabe28b9d76ca4eecf37922402df93 , < b63e120189fd92aff00096d11e2fc5253f60248b (git)
    Affected: 85a8ce62c2eabe28b9d76ca4eecf37922402df93 , < 4633a79ff8bc82770486a063a08b55e5162521d8 (git)
    Affected: 85a8ce62c2eabe28b9d76ca4eecf37922402df93 , < 941d5180c430ce5b0f7a3622ef9b76077bfa3d82 (git)
    Affected: 85a8ce62c2eabe28b9d76ca4eecf37922402df93 , < 3ee859e384d453d6ac68bfd5971f630d9fa46ad3 (git)
    Affected: 5.4.9 , < 5.4.176 (semver)
    Create a notification for this product.
    Linux Linux Affected: 5.5
    Unaffected: 0 , < 5.5 (semver)
    Unaffected: 5.4.176 , ≤ 5.4.* (semver)
    Unaffected: 5.10.96 , ≤ 5.10.* (semver)
    Unaffected: 5.15.19 , ≤ 5.15.* (semver)
    Unaffected: 5.16.5 , ≤ 5.16.* (semver)
    Unaffected: 5.17 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < 6cbf4c731d78 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < b63e120189fd (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < 4633a79ff8bc (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < 941d5180c430 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < 3ee859e384d4 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.4.176 , ≤ 5.5 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.10.96 , ≤ 5.11 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.15.19 , ≤ 5.16 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.16.5 , ≤ 5.17 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.17
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6cbf4c731d78",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "b63e120189fd",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "4633a79ff8bc",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "941d5180c430",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3ee859e384d4",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.5",
                    "status": "unaffected",
                    "version": "5.4.176",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.11",
                    "status": "unaffected",
                    "version": "5.10.96",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.16",
                    "status": "unaffected",
                    "version": "5.15.19",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.17",
                    "status": "unaffected",
                    "version": "5.16.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "5.17"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-48747",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-26T14:56:40.641058Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-908",
                    "description": "CWE-908 Use of Uninitialized Resource",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-22T13:28:21.215Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T15:25:01.583Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/6cbf4c731d7812518cd857c2cfc3da9fd120f6ae"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/b63e120189fd92aff00096d11e2fc5253f60248b"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/4633a79ff8bc82770486a063a08b55e5162521d8"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/941d5180c430ce5b0f7a3622ef9b76077bfa3d82"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/3ee859e384d453d6ac68bfd5971f630d9fa46ad3"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "block/bio.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "6cbf4c731d7812518cd857c2cfc3da9fd120f6ae",
                  "status": "affected",
                  "version": "943cd69efac437d82a7aea0659fccbcc071730de",
                  "versionType": "git"
                },
                {
                  "lessThan": "b63e120189fd92aff00096d11e2fc5253f60248b",
                  "status": "affected",
                  "version": "85a8ce62c2eabe28b9d76ca4eecf37922402df93",
                  "versionType": "git"
                },
                {
                  "lessThan": "4633a79ff8bc82770486a063a08b55e5162521d8",
                  "status": "affected",
                  "version": "85a8ce62c2eabe28b9d76ca4eecf37922402df93",
                  "versionType": "git"
                },
                {
                  "lessThan": "941d5180c430ce5b0f7a3622ef9b76077bfa3d82",
                  "status": "affected",
                  "version": "85a8ce62c2eabe28b9d76ca4eecf37922402df93",
                  "versionType": "git"
                },
                {
                  "lessThan": "3ee859e384d453d6ac68bfd5971f630d9fa46ad3",
                  "status": "affected",
                  "version": "85a8ce62c2eabe28b9d76ca4eecf37922402df93",
                  "versionType": "git"
                },
                {
                  "lessThan": "5.4.176",
                  "status": "affected",
                  "version": "5.4.9",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "block/bio.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.5"
                },
                {
                  "lessThan": "5.5",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.176",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.96",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.19",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.16.*",
                  "status": "unaffected",
                  "version": "5.16.5",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "5.17",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.176",
                      "versionStartIncluding": "5.4.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.96",
                      "versionStartIncluding": "5.5",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.19",
                      "versionStartIncluding": "5.5",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.16.5",
                      "versionStartIncluding": "5.5",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.17",
                      "versionStartIncluding": "5.5",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: Fix wrong offset in bio_truncate()\n\nbio_truncate() clears the buffer outside of last block of bdev, however\ncurrent bio_truncate() is using the wrong offset of page. So it can\nreturn the uninitialized data.\n\nThis happened when both of truncated/corrupted FS and userspace (via\nbdev) are trying to read the last of bdev."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-23T15:20:36.508Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/6cbf4c731d7812518cd857c2cfc3da9fd120f6ae"
            },
            {
              "url": "https://git.kernel.org/stable/c/b63e120189fd92aff00096d11e2fc5253f60248b"
            },
            {
              "url": "https://git.kernel.org/stable/c/4633a79ff8bc82770486a063a08b55e5162521d8"
            },
            {
              "url": "https://git.kernel.org/stable/c/941d5180c430ce5b0f7a3622ef9b76077bfa3d82"
            },
            {
              "url": "https://git.kernel.org/stable/c/3ee859e384d453d6ac68bfd5971f630d9fa46ad3"
            }
          ],
          "title": "block: Fix wrong offset in bio_truncate()",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2022-48747",
        "datePublished": "2024-06-20T11:13:29.951Z",
        "dateReserved": "2024-06-20T11:09:39.055Z",
        "dateUpdated": "2026-05-23T15:20:36.508Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2022-48716 (GCVE-0-2022-48716)

    Vulnerability from cvelistv5 – Published: 2024-06-20 11:13 – Updated: 2026-08-05 08:51
    VLAI
    Title
    ASoC: codecs: wcd938x: fix incorrect used of portid
    Summary
    In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd938x: fix incorrect used of portid Mixer controls have the channel id in mixer->reg, which is not same as port id. port id should be derived from chan_info array. So fix this. Without this, its possible that we could corrupt struct wcd938x_sdw_priv by accessing port_map array out of range with channel id instead of port id.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-25 13:56 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    Linux Linux Affected: e8ba1e05bdc016700c85fad559a812c2e795442f , < aa7152f9f117b3e66b3c0d4158ca4c6d46ab229f (git)
    Affected: e8ba1e05bdc016700c85fad559a812c2e795442f , < 9167f2712dc8c24964840a4d1e2ebf130e846b95 (git)
    Affected: e8ba1e05bdc016700c85fad559a812c2e795442f , < c5c1546a654f613e291a7c5d6f3660fc1eb6d0c7 (git)
    Create a notification for this product.
    Linux Linux Affected: 5.14
    Unaffected: 0 , < 5.14 (semver)
    Unaffected: 5.15.22 , ≤ 5.15.* (semver)
    Unaffected: 5.16.8 , ≤ 5.16.* (semver)
    Unaffected: 5.17 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: e8ba1e05bdc0 , < aa7152f9f117 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: e8ba1e05bdc0 , < 9167f2712dc8 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: e8ba1e05bdc0 , < c5c1546a654f (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 5.14
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 5.14 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.15.22 , ≤ 5.16 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.16.8 , ≤ 5.17 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.17
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "aa7152f9f117",
                    "status": "affected",
                    "version": "e8ba1e05bdc0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "9167f2712dc8",
                    "status": "affected",
                    "version": "e8ba1e05bdc0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "c5c1546a654f",
                    "status": "affected",
                    "version": "e8ba1e05bdc0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.14"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.14",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.16",
                    "status": "unaffected",
                    "version": "5.15.22",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.17",
                    "status": "unaffected",
                    "version": "5.16.8",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "5.17"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-48716",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-25T13:56:06.745366Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-25T14:04:19.940Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T15:17:55.862Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/aa7152f9f117b3e66b3c0d4158ca4c6d46ab229f"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/9167f2712dc8c24964840a4d1e2ebf130e846b95"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/c5c1546a654f613e291a7c5d6f3660fc1eb6d0c7"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "sound/soc/codecs/wcd938x.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "aa7152f9f117b3e66b3c0d4158ca4c6d46ab229f",
                  "status": "affected",
                  "version": "e8ba1e05bdc016700c85fad559a812c2e795442f",
                  "versionType": "git"
                },
                {
                  "lessThan": "9167f2712dc8c24964840a4d1e2ebf130e846b95",
                  "status": "affected",
                  "version": "e8ba1e05bdc016700c85fad559a812c2e795442f",
                  "versionType": "git"
                },
                {
                  "lessThan": "c5c1546a654f613e291a7c5d6f3660fc1eb6d0c7",
                  "status": "affected",
                  "version": "e8ba1e05bdc016700c85fad559a812c2e795442f",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "sound/soc/codecs/wcd938x.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.14"
                },
                {
                  "lessThan": "5.14",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.22",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.16.*",
                  "status": "unaffected",
                  "version": "5.16.8",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "5.17",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.22",
                      "versionStartIncluding": "5.14",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.16.8",
                      "versionStartIncluding": "5.14",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.17",
                      "versionStartIncluding": "5.14",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: wcd938x: fix incorrect used of portid\n\nMixer controls have the channel id in mixer-\u003ereg, which is not same\nas port id. port id should be derived from chan_info array.\nSo fix this. Without this, its possible that we could corrupt\nstruct wcd938x_sdw_priv by accessing port_map array out of range\nwith channel id instead of port id."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The bug is reached by writing ALSA mixer controls (e.g. DSD_L/DSD_R Switch) via ioctl on /dev/snd/controlC*, a local device-file interface; it is not reachable from the network stack or remote protocols.\nAC:L - An attacker who can open the sound control device can reliably toggle the fixed DSD mixer controls; no race, non-deterministic state, or other condition outside attacker control is required.\nPR:L - snd_ctl_elem_write performs no capability check; access depends only on /dev/snd/controlC* permissions, typically granted to unprivileged audio-group users on affected Qualcomm devices (phones, Chromebooks, ThinkPad X13s), not real root.\nUI:N - The attacker triggers the OOB write directly by writing the mixer control; no separate victim action is required.\nS:U - This is standard in-kernel memory corruption of wcd938x_sdw_priv with impact confined to the host kernel\u0027s security authority, not a VM/IOMMU/sandbox boundary cross.\nC:H - The OOB write corrupts the adjacent ch_info pointer inside wcd938x_sdw_priv; subsequent use of that corrupted pointer enables kernel memory disclosure primitives, so confidentiality impact is High.\nI:H - Out-of-bounds write into port_config[port_num] (port 5 / DSD) overwrites trailing structure fields and yields kernel memory corruption exploitable for integrity compromise and control-flow hijacking.\nA:H - Dereferencing the corrupted ch_info pointer after the OOB write can oops/panic the kernel, causing a full availability loss."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T08:51:53.731Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/aa7152f9f117b3e66b3c0d4158ca4c6d46ab229f"
            },
            {
              "url": "https://git.kernel.org/stable/c/9167f2712dc8c24964840a4d1e2ebf130e846b95"
            },
            {
              "url": "https://git.kernel.org/stable/c/c5c1546a654f613e291a7c5d6f3660fc1eb6d0c7"
            }
          ],
          "title": "ASoC: codecs: wcd938x: fix incorrect used of portid",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2022-48716",
        "datePublished": "2024-06-20T11:13:09.315Z",
        "dateReserved": "2024-06-20T11:09:39.050Z",
        "dateUpdated": "2026-08-05T08:51:53.731Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-38616 (GCVE-0-2024-38616)

    Vulnerability from cvelistv5 – Published: 2024-06-19 13:56 – Updated: 2026-05-11 20:20
    VLAI
    Title
    wifi: carl9170: re-fix fortified-memset warning
    Summary
    In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: re-fix fortified-memset warning The carl9170_tx_release() function sometimes triggers a fortified-memset warning in my randconfig builds: In file included from include/linux/string.h:254, from drivers/net/wireless/ath/carl9170/tx.c:40: In function 'fortify_memset_chk', inlined from 'carl9170_tx_release' at drivers/net/wireless/ath/carl9170/tx.c:283:2, inlined from 'kref_put' at include/linux/kref.h:65:3, inlined from 'carl9170_tx_put_skb' at drivers/net/wireless/ath/carl9170/tx.c:342:9: include/linux/fortify-string.h:493:25: error: call to '__write_overflow_field' declared with attribute warning: detected write beyond size of field (1st parameter); maybe use struct_group()? [-Werror=attribute-warning] 493 | __write_overflow_field(p_size_field, size); Kees previously tried to avoid this by using memset_after(), but it seems this does not fully address the problem. I noticed that the memset_after() here is done on a different part of the union (status) than the original cast was from (rate_driver_data), which may confuse the compiler. Unfortunately, the memset_after() trick does not work on driver_rates[] because that is part of an anonymous struct, and I could not get struct_group() to do this either. Using two separate memset() calls on the two members does address the warning though.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-20 13:37 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    Linux Linux Affected: fb5f6a0e8063b7a84d6d44ef353846ccd7708d2e , < 13857683126e8a6492af73c74d702835f7a2175b (git)
    Affected: fb5f6a0e8063b7a84d6d44ef353846ccd7708d2e , < 87586467098281f04fa93e59fe3a516b954bddc4 (git)
    Affected: fb5f6a0e8063b7a84d6d44ef353846ccd7708d2e , < 0c38c9c460bb8ce8d6f6cf316e0d71a70983ec83 (git)
    Affected: fb5f6a0e8063b7a84d6d44ef353846ccd7708d2e , < 042a39bb8e0812466327a5102606e88a5a4f8c02 (git)
    Affected: fb5f6a0e8063b7a84d6d44ef353846ccd7708d2e , < 066afafc10c9476ee36c47c9062527a17e763901 (git)
    Create a notification for this product.
    Linux Linux Affected: 5.17
    Unaffected: 0 , < 5.17 (semver)
    Unaffected: 6.1.93 , ≤ 6.1.* (semver)
    Unaffected: 6.6.33 , ≤ 6.6.* (semver)
    Unaffected: 6.8.12 , ≤ 6.8.* (semver)
    Unaffected: 6.9.3 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: fb5f6a0e8063 , < 13857683126e (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: fb5f6a0e8063 , < 875864670982 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: fb5f6a0e8063 , < 0c38c9c460bb (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: fb5f6a0e8063 , < 042a39bb8e08 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: fb5f6a0e8063 , < 066afafc10c9 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 5.17
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 5.17 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.1.93 , ≤ 6.2 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.33 , ≤ 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.8.12 , ≤ 6.9 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9.3 t , ≤ 6.10 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.10_rc1
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "13857683126e",
                    "status": "affected",
                    "version": "fb5f6a0e8063",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "875864670982",
                    "status": "affected",
                    "version": "fb5f6a0e8063",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "0c38c9c460bb",
                    "status": "affected",
                    "version": "fb5f6a0e8063",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "042a39bb8e08",
                    "status": "affected",
                    "version": "fb5f6a0e8063",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "066afafc10c9",
                    "status": "affected",
                    "version": "fb5f6a0e8063",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.17"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.17",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.2",
                    "status": "unaffected",
                    "version": "6.1.93",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.7",
                    "status": "unaffected",
                    "version": "6.6.33",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.9",
                    "status": "unaffected",
                    "version": "6.8.12",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.10",
                    "status": "unaffected",
                    "version": "6.9.3 t",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.10_rc1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.2,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-38616",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-20T13:37:04.448058Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-20T15:06:00.634Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T04:12:26.016Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/13857683126e8a6492af73c74d702835f7a2175b"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/87586467098281f04fa93e59fe3a516b954bddc4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/0c38c9c460bb8ce8d6f6cf316e0d71a70983ec83"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/042a39bb8e0812466327a5102606e88a5a4f8c02"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/066afafc10c9476ee36c47c9062527a17e763901"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/net/wireless/ath/carl9170/tx.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "13857683126e8a6492af73c74d702835f7a2175b",
                  "status": "affected",
                  "version": "fb5f6a0e8063b7a84d6d44ef353846ccd7708d2e",
                  "versionType": "git"
                },
                {
                  "lessThan": "87586467098281f04fa93e59fe3a516b954bddc4",
                  "status": "affected",
                  "version": "fb5f6a0e8063b7a84d6d44ef353846ccd7708d2e",
                  "versionType": "git"
                },
                {
                  "lessThan": "0c38c9c460bb8ce8d6f6cf316e0d71a70983ec83",
                  "status": "affected",
                  "version": "fb5f6a0e8063b7a84d6d44ef353846ccd7708d2e",
                  "versionType": "git"
                },
                {
                  "lessThan": "042a39bb8e0812466327a5102606e88a5a4f8c02",
                  "status": "affected",
                  "version": "fb5f6a0e8063b7a84d6d44ef353846ccd7708d2e",
                  "versionType": "git"
                },
                {
                  "lessThan": "066afafc10c9476ee36c47c9062527a17e763901",
                  "status": "affected",
                  "version": "fb5f6a0e8063b7a84d6d44ef353846ccd7708d2e",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/net/wireless/ath/carl9170/tx.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.17"
                },
                {
                  "lessThan": "5.17",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.93",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.33",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.12",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.93",
                      "versionStartIncluding": "5.17",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.33",
                      "versionStartIncluding": "5.17",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.12",
                      "versionStartIncluding": "5.17",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.3",
                      "versionStartIncluding": "5.17",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "5.17",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: re-fix fortified-memset warning\n\nThe carl9170_tx_release() function sometimes triggers a fortified-memset\nwarning in my randconfig builds:\n\nIn file included from include/linux/string.h:254,\n                 from drivers/net/wireless/ath/carl9170/tx.c:40:\nIn function \u0027fortify_memset_chk\u0027,\n    inlined from \u0027carl9170_tx_release\u0027 at drivers/net/wireless/ath/carl9170/tx.c:283:2,\n    inlined from \u0027kref_put\u0027 at include/linux/kref.h:65:3,\n    inlined from \u0027carl9170_tx_put_skb\u0027 at drivers/net/wireless/ath/carl9170/tx.c:342:9:\ninclude/linux/fortify-string.h:493:25: error: call to \u0027__write_overflow_field\u0027 declared with attribute warning: detected write beyond size of field (1st parameter); maybe use struct_group()? [-Werror=attribute-warning]\n  493 |                         __write_overflow_field(p_size_field, size);\n\nKees previously tried to avoid this by using memset_after(), but it seems\nthis does not fully address the problem. I noticed that the memset_after()\nhere is done on a different part of the union (status) than the original\ncast was from (rate_driver_data), which may confuse the compiler.\n\nUnfortunately, the memset_after() trick does not work on driver_rates[]\nbecause that is part of an anonymous struct, and I could not get\nstruct_group() to do this either. Using two separate memset() calls\non the two members does address the warning though."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T20:20:13.311Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/13857683126e8a6492af73c74d702835f7a2175b"
            },
            {
              "url": "https://git.kernel.org/stable/c/87586467098281f04fa93e59fe3a516b954bddc4"
            },
            {
              "url": "https://git.kernel.org/stable/c/0c38c9c460bb8ce8d6f6cf316e0d71a70983ec83"
            },
            {
              "url": "https://git.kernel.org/stable/c/042a39bb8e0812466327a5102606e88a5a4f8c02"
            },
            {
              "url": "https://git.kernel.org/stable/c/066afafc10c9476ee36c47c9062527a17e763901"
            }
          ],
          "title": "wifi: carl9170: re-fix fortified-memset warning",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-38616",
        "datePublished": "2024-06-19T13:56:16.086Z",
        "dateReserved": "2024-06-18T19:36:34.944Z",
        "dateUpdated": "2026-05-11T20:20:13.311Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-38612 (GCVE-0-2024-38612)

    Vulnerability from cvelistv5 – Published: 2024-06-19 13:56 – Updated: 2026-08-05 11:33
    VLAI
    Title
    ipv6: sr: fix invalid unregister error path
    Summary
    In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defined. In that case if seg6_hmac_init() fails, the genl_unregister_family() isn't called. This issue exist since commit 46738b1317e1 ("ipv6: sr: add option to control lwtunnel support"), and commit 5559cea2d5aa ("ipv6: sr: fix possible use-after-free and null-ptr-deref") replaced unregister_pernet_subsys() with genl_unregister_family() in this error path.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-25 14:07 UTC
    CWE
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 46738b1317e169b281ad74690276916e24d1be6d , < 10610575a3ac2a702bf5c57aa931beaf847949c7 (git)
    Affected: 46738b1317e169b281ad74690276916e24d1be6d , < 646cd236c55e2cb5f146fc41bbe4034c4af5b2a4 (git)
    Affected: 46738b1317e169b281ad74690276916e24d1be6d , < 00e6335329f23ac6cf3105931691674e28bc598c (git)
    Affected: 46738b1317e169b281ad74690276916e24d1be6d , < 1a63730fb315bb1bab97edd69ff58ad45e04bb01 (git)
    Affected: 46738b1317e169b281ad74690276916e24d1be6d , < e77a3ec7ada84543e75722a1283785a6544de925 (git)
    Affected: 46738b1317e169b281ad74690276916e24d1be6d , < 3398a40dccb88d3a7eef378247a023a78472db66 (git)
    Affected: 46738b1317e169b281ad74690276916e24d1be6d , < 85a70ff1e572160f1eeb096ed48d09a1c9d4d89a (git)
    Affected: 46738b1317e169b281ad74690276916e24d1be6d , < c04d6a914e890ccea4a9d11233009a2ee7978bf4 (git)
    Affected: 46738b1317e169b281ad74690276916e24d1be6d , < 160e9d2752181fcf18c662e74022d77d3164cd45 (git)
    Create a notification for this product.
    Linux Linux Affected: 4.10
    Unaffected: 0 , < 4.10 (semver)
    Unaffected: 4.19.316 , ≤ 4.19.* (semver)
    Unaffected: 5.4.278 , ≤ 5.4.* (semver)
    Unaffected: 5.10.219 , ≤ 5.10.* (semver)
    Unaffected: 5.15.161 , ≤ 5.15.* (semver)
    Unaffected: 6.1.93 , ≤ 6.1.* (semver)
    Unaffected: 6.6.33 , ≤ 6.6.* (semver)
    Unaffected: 6.8.12 , ≤ 6.8.* (semver)
    Unaffected: 6.9.3 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 46738b1317e1 , < 0610575a3ac (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 46738b1317e1 , < 646cd236c55e (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 46738b1317e1 , < 00e6335329f2 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 46738b1317e1 , < 1a63730fb315 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 46738b1317e1 , < e77a3ec7ada8 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 46738b1317e1 , < 3398a40dccb8 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 46738b1317e1 , < 85a70ff1e572 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 46738b1317e1 , < c04d6a914e89 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 46738b1317e1 , < 160e9d275218 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 4.10
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 4.10 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 4.19.316 , ≤ 4.20 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.4.278 , ≤ 5.5 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux acrn Unaffected: 5.10.219 , ≤ 5.11 (custom)
        cpe:2.3:o:linux:acrn:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.15.161 , ≤ 5.16 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.1.93 , ≤ 6.2 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.33 , ≤ 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.8.12 , ≤ 6.9 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9.3 , ≤ 6.10 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.10-rc1
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Siemens RUGGEDCOM RST2428P Affected: 0 , < V3.1 (custom)
    Create a notification for this product.
    Siemens SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family Unaffected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SCALANCE XCM-/XRM-/XCH-/XRH-300 family Affected: 0 , < V3.1 (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.0 , < V3.1.5 (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP Affected: V3.1.0 , < V3.1.5 (custom)
    Create a notification for this product.
    Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.0 , < V3.1.5 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "0610575a3ac",
                    "status": "affected",
                    "version": "46738b1317e1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "646cd236c55e",
                    "status": "affected",
                    "version": "46738b1317e1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "00e6335329f2",
                    "status": "affected",
                    "version": "46738b1317e1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "1a63730fb315",
                    "status": "affected",
                    "version": "46738b1317e1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "e77a3ec7ada8",
                    "status": "affected",
                    "version": "46738b1317e1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3398a40dccb8",
                    "status": "affected",
                    "version": "46738b1317e1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "85a70ff1e572",
                    "status": "affected",
                    "version": "46738b1317e1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "c04d6a914e89",
                    "status": "affected",
                    "version": "46738b1317e1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "160e9d275218",
                    "status": "affected",
                    "version": "46738b1317e1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.10"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "4.10",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "4.20",
                    "status": "unaffected",
                    "version": "4.19.316",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.5",
                    "status": "unaffected",
                    "version": "5.4.278",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:acrn:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "acrn",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.11",
                    "status": "unaffected",
                    "version": "5.10.219",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.16",
                    "status": "unaffected",
                    "version": "5.15.161",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.2",
                    "status": "unaffected",
                    "version": "6.1.93",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.7",
                    "status": "unaffected",
                    "version": "6.6.33",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.9",
                    "status": "unaffected",
                    "version": "6.8.12",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.10",
                    "status": "unaffected",
                    "version": "6.9.3",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.10-rc1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-38612",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-25T14:07:52.263547Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-476",
                    "description": "CWE-476 NULL Pointer Dereference",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              },
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-25T14:37:58.950Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-04T17:21:46.235Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/10610575a3ac2a702bf5c57aa931beaf847949c7"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/646cd236c55e2cb5f146fc41bbe4034c4af5b2a4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/00e6335329f23ac6cf3105931691674e28bc598c"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/1a63730fb315bb1bab97edd69ff58ad45e04bb01"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/e77a3ec7ada84543e75722a1283785a6544de925"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/3398a40dccb88d3a7eef378247a023a78472db66"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/85a70ff1e572160f1eeb096ed48d09a1c9d4d89a"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/c04d6a914e890ccea4a9d11233009a2ee7978bf4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/160e9d2752181fcf18c662e74022d77d3164cd45"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "RUGGEDCOM RST2428P",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SCALANCE XCM-/XRM-/XCH-/XRH-300 family",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T11:55:09.566Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-398330.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-613116.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/ipv6/seg6.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "10610575a3ac2a702bf5c57aa931beaf847949c7",
                  "status": "affected",
                  "version": "46738b1317e169b281ad74690276916e24d1be6d",
                  "versionType": "git"
                },
                {
                  "lessThan": "646cd236c55e2cb5f146fc41bbe4034c4af5b2a4",
                  "status": "affected",
                  "version": "46738b1317e169b281ad74690276916e24d1be6d",
                  "versionType": "git"
                },
                {
                  "lessThan": "00e6335329f23ac6cf3105931691674e28bc598c",
                  "status": "affected",
                  "version": "46738b1317e169b281ad74690276916e24d1be6d",
                  "versionType": "git"
                },
                {
                  "lessThan": "1a63730fb315bb1bab97edd69ff58ad45e04bb01",
                  "status": "affected",
                  "version": "46738b1317e169b281ad74690276916e24d1be6d",
                  "versionType": "git"
                },
                {
                  "lessThan": "e77a3ec7ada84543e75722a1283785a6544de925",
                  "status": "affected",
                  "version": "46738b1317e169b281ad74690276916e24d1be6d",
                  "versionType": "git"
                },
                {
                  "lessThan": "3398a40dccb88d3a7eef378247a023a78472db66",
                  "status": "affected",
                  "version": "46738b1317e169b281ad74690276916e24d1be6d",
                  "versionType": "git"
                },
                {
                  "lessThan": "85a70ff1e572160f1eeb096ed48d09a1c9d4d89a",
                  "status": "affected",
                  "version": "46738b1317e169b281ad74690276916e24d1be6d",
                  "versionType": "git"
                },
                {
                  "lessThan": "c04d6a914e890ccea4a9d11233009a2ee7978bf4",
                  "status": "affected",
                  "version": "46738b1317e169b281ad74690276916e24d1be6d",
                  "versionType": "git"
                },
                {
                  "lessThan": "160e9d2752181fcf18c662e74022d77d3164cd45",
                  "status": "affected",
                  "version": "46738b1317e169b281ad74690276916e24d1be6d",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/ipv6/seg6.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.10"
                },
                {
                  "lessThan": "4.10",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "4.19.*",
                  "status": "unaffected",
                  "version": "4.19.316",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.278",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.219",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.161",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.93",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.33",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.12",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.19.316",
                      "versionStartIncluding": "4.10",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.278",
                      "versionStartIncluding": "4.10",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.219",
                      "versionStartIncluding": "4.10",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.161",
                      "versionStartIncluding": "4.10",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.93",
                      "versionStartIncluding": "4.10",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.33",
                      "versionStartIncluding": "4.10",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.12",
                      "versionStartIncluding": "4.10",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.3",
                      "versionStartIncluding": "4.10",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "4.10",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sr: fix invalid unregister error path\n\nThe error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL\nis not defined. In that case if seg6_hmac_init() fails, the\ngenl_unregister_family() isn\u0027t called.\n\nThis issue exist since commit 46738b1317e1 (\"ipv6: sr: add option to control\nlwtunnel support\"), and commit 5559cea2d5aa (\"ipv6: sr: fix possible\nuse-after-free and null-ptr-deref\") replaced unregister_pernet_subsys()\nwith genl_unregister_family() in this error path."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The leaked `seg6_genl_family` is reached through generic netlink sockets (`nlctrl` family enumeration or `SEG6_CMD_*` messages), which require local system access. No remote packet path reaches the stale registration.\nAC:H - The corrupt state only arises if `seg6_hmac_init()` fails during one-shot module/boot init (an ENOMEM or missing-crypto condition an attacker cannot reliably force), and only on the uncommon `CONFIG_IPV6_SEG6_HMAC=y` with `CONFIG_IPV6_SEG6_LWTUNNEL=n` configuration, since distros that enable HMAC normally also enable LWTUNNEL.\nPR:L - Once the family is leaked, any unprivileged local user can dereference the stale `struct genl_family` via `CTRL_CMD_GETFAMILY`/dump on `nlctrl`, which carries no capability check; in the module case even the `GENL_ADMIN_PERM` flag is read out of the freed memory, so the privilege gate itself is unreliable.\nUI:N - Exploitation needs only the attacker\u0027s own netlink socket operations after the failed init; no victim action is involved.\nS:U - The dangling family struct, freed pernet data, and any resulting code execution all remain within the kernel\u0027s own security authority \u2014 no VM, IOMMU, or sandbox boundary is crossed.\nC:H - `CTRL_CMD_GETFAMILY` copies `name`, `version`, `maxattr`, and the op list out of the freed module region into a netlink reply, and `SEG6_CMD_GET_TUNSRC` returns data read through the freed `seg6_pernet_data`, disclosing reclaimed kernel memory to userspace.\nI:H - The use-after-free supplies write primitives \u2014 `SEG6_CMD_SET_TUNSRC` writes an attacker-supplied IPv6 address into freed memory and `SEG6_CMD_SETHMAC` mutates a freed rhashtable \u2014 while the stale `family-\u003eops[].doit`/`pre_doit` pointers in freed module memory offer control-flow hijack.\nA:H - Dereferencing the freed family struct or the dangling `net-\u003eipv6.seg6_data` produces a use-after-free oops, and netns created after the failure yield a NULL-pointer dereference, either of which panics the kernel."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:33:11.285Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/10610575a3ac2a702bf5c57aa931beaf847949c7"
            },
            {
              "url": "https://git.kernel.org/stable/c/646cd236c55e2cb5f146fc41bbe4034c4af5b2a4"
            },
            {
              "url": "https://git.kernel.org/stable/c/00e6335329f23ac6cf3105931691674e28bc598c"
            },
            {
              "url": "https://git.kernel.org/stable/c/1a63730fb315bb1bab97edd69ff58ad45e04bb01"
            },
            {
              "url": "https://git.kernel.org/stable/c/e77a3ec7ada84543e75722a1283785a6544de925"
            },
            {
              "url": "https://git.kernel.org/stable/c/3398a40dccb88d3a7eef378247a023a78472db66"
            },
            {
              "url": "https://git.kernel.org/stable/c/85a70ff1e572160f1eeb096ed48d09a1c9d4d89a"
            },
            {
              "url": "https://git.kernel.org/stable/c/c04d6a914e890ccea4a9d11233009a2ee7978bf4"
            },
            {
              "url": "https://git.kernel.org/stable/c/160e9d2752181fcf18c662e74022d77d3164cd45"
            }
          ],
          "title": "ipv6: sr: fix invalid unregister error path",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-38612",
        "datePublished": "2024-06-19T13:56:13.415Z",
        "dateReserved": "2024-06-18T19:36:34.944Z",
        "dateUpdated": "2026-08-05T11:33:11.285Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-38605 (GCVE-0-2024-38605)

    Vulnerability from cvelistv5 – Published: 2024-06-19 13:48 – Updated: 2026-08-05 11:33
    VLAI
    Title
    ALSA: core: Fix NULL module pointer assignment at card init
    Summary
    In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix NULL module pointer assignment at card init The commit 81033c6b584b ("ALSA: core: Warn on empty module") introduced a WARN_ON() for a NULL module pointer passed at snd_card object creation, and it also wraps the code around it with '#ifdef MODULE'. This works in most cases, but the devils are always in details. "MODULE" is defined when the target code (i.e. the sound core) is built as a module; but this doesn't mean that the caller is also built-in or not. Namely, when only the sound core is built-in (CONFIG_SND=y) while the driver is a module (CONFIG_SND_USB_AUDIO=m), the passed module pointer is ignored even if it's non-NULL, and card->module remains as NULL. This would result in the missing module reference up/down at the device open/close, leading to a race with the code execution after the module removal. For addressing the bug, move the assignment of card->module again out of ifdef. The WARN_ON() is still wrapped with ifdef because the module can be really NULL when all sound drivers are built-in. Note that we keep 'ifdef MODULE' for WARN_ON(), otherwise it would lead to a false-positive NULL module check. Admittedly it won't catch perfectly, i.e. no check is performed when CONFIG_SND=y. But, it's no real problem as it's only for debugging, and the condition is pretty rare.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-27 17:45 UTC
    CWE
    • CWE-476 - NULL Pointer Dereference
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 81033c6b584b44514cbb16fffc26ca29a0fa6270 , < d7ff29a429b56f04783152ad7bbd7233b740e434 (git)
    Affected: 81033c6b584b44514cbb16fffc26ca29a0fa6270 , < e7e0ca200772bdb2fdc6d43d32d341e87a36f811 (git)
    Affected: 81033c6b584b44514cbb16fffc26ca29a0fa6270 , < e007476725730c1a68387b54b7629486d8a8301e (git)
    Affected: 81033c6b584b44514cbb16fffc26ca29a0fa6270 , < e644036a3e2b2c9b3eee3c61b5d31c2ca8b5ba92 (git)
    Affected: 81033c6b584b44514cbb16fffc26ca29a0fa6270 , < c935e72139e6d523defd60fe875c01eb1f9ea5c5 (git)
    Affected: 81033c6b584b44514cbb16fffc26ca29a0fa6270 , < 6b8374ee2cabcf034faa34e69a855dc496a9ec12 (git)
    Affected: 81033c6b584b44514cbb16fffc26ca29a0fa6270 , < 39381fe7394e5eafac76e7e9367e7351138a29c1 (git)
    Create a notification for this product.
    Linux Linux Affected: 5.9
    Unaffected: 0 , < 5.9 (semver)
    Unaffected: 5.10.219 , ≤ 5.10.* (semver)
    Unaffected: 5.15.161 , ≤ 5.15.* (semver)
    Unaffected: 6.1.93 , ≤ 6.1.* (semver)
    Unaffected: 6.6.33 , ≤ 6.6.* (semver)
    Unaffected: 6.8.12 , ≤ 6.8.* (semver)
    Unaffected: 6.9.3 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 81033c6b584b , < d7ff29a429b5 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 81033c6b584b , < e7e0ca200772 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 81033c6b584b , < e00747672573 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 81033c6b584b , < e644036a3e2b (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 81033c6b584b , < c935e72139e6 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 81033c6b584b , < 6b8374ee2cab (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 81033c6b584b , < 39381fe7394e (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 5.9
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 5.9 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.10.219 , ≤ 5.11 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.15.161 , ≤ 5.16 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.1.93 , ≤ 6.2 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.33 , ≤ 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.8.12 , ≤ 6.9 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9.3 , ≤ 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.10-rc1
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "d7ff29a429b5",
                    "status": "affected",
                    "version": "81033c6b584b",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "e7e0ca200772",
                    "status": "affected",
                    "version": "81033c6b584b",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "e00747672573",
                    "status": "affected",
                    "version": "81033c6b584b",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "e644036a3e2b",
                    "status": "affected",
                    "version": "81033c6b584b",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "c935e72139e6",
                    "status": "affected",
                    "version": "81033c6b584b",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6b8374ee2cab",
                    "status": "affected",
                    "version": "81033c6b584b",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "39381fe7394e",
                    "status": "affected",
                    "version": "81033c6b584b",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.9"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.9",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.11",
                    "status": "unaffected",
                    "version": "5.10.219",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.16",
                    "status": "unaffected",
                    "version": "5.15.161",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.2",
                    "status": "unaffected",
                    "version": "6.1.93",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.7",
                    "status": "unaffected",
                    "version": "6.6.33",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.9",
                    "status": "unaffected",
                    "version": "6.8.12",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.7",
                    "status": "unaffected",
                    "version": "6.9.3",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.10-rc1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-38605",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-27T17:45:58.997847Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-476",
                    "description": "CWE-476 NULL Pointer Dereference",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-27T18:08:30.086Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T04:12:25.960Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/d7ff29a429b56f04783152ad7bbd7233b740e434"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/e7e0ca200772bdb2fdc6d43d32d341e87a36f811"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/e007476725730c1a68387b54b7629486d8a8301e"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/e644036a3e2b2c9b3eee3c61b5d31c2ca8b5ba92"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/c935e72139e6d523defd60fe875c01eb1f9ea5c5"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/6b8374ee2cabcf034faa34e69a855dc496a9ec12"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/39381fe7394e5eafac76e7e9367e7351138a29c1"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "sound/core/init.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "d7ff29a429b56f04783152ad7bbd7233b740e434",
                  "status": "affected",
                  "version": "81033c6b584b44514cbb16fffc26ca29a0fa6270",
                  "versionType": "git"
                },
                {
                  "lessThan": "e7e0ca200772bdb2fdc6d43d32d341e87a36f811",
                  "status": "affected",
                  "version": "81033c6b584b44514cbb16fffc26ca29a0fa6270",
                  "versionType": "git"
                },
                {
                  "lessThan": "e007476725730c1a68387b54b7629486d8a8301e",
                  "status": "affected",
                  "version": "81033c6b584b44514cbb16fffc26ca29a0fa6270",
                  "versionType": "git"
                },
                {
                  "lessThan": "e644036a3e2b2c9b3eee3c61b5d31c2ca8b5ba92",
                  "status": "affected",
                  "version": "81033c6b584b44514cbb16fffc26ca29a0fa6270",
                  "versionType": "git"
                },
                {
                  "lessThan": "c935e72139e6d523defd60fe875c01eb1f9ea5c5",
                  "status": "affected",
                  "version": "81033c6b584b44514cbb16fffc26ca29a0fa6270",
                  "versionType": "git"
                },
                {
                  "lessThan": "6b8374ee2cabcf034faa34e69a855dc496a9ec12",
                  "status": "affected",
                  "version": "81033c6b584b44514cbb16fffc26ca29a0fa6270",
                  "versionType": "git"
                },
                {
                  "lessThan": "39381fe7394e5eafac76e7e9367e7351138a29c1",
                  "status": "affected",
                  "version": "81033c6b584b44514cbb16fffc26ca29a0fa6270",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "sound/core/init.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.9"
                },
                {
                  "lessThan": "5.9",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.219",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.161",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.93",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.33",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.12",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.219",
                      "versionStartIncluding": "5.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.161",
                      "versionStartIncluding": "5.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.93",
                      "versionStartIncluding": "5.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.33",
                      "versionStartIncluding": "5.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.12",
                      "versionStartIncluding": "5.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.3",
                      "versionStartIncluding": "5.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "5.9",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: core: Fix NULL module pointer assignment at card init\n\nThe commit 81033c6b584b (\"ALSA: core: Warn on empty module\")\nintroduced a WARN_ON() for a NULL module pointer passed at snd_card\nobject creation, and it also wraps the code around it with \u0027#ifdef\nMODULE\u0027.  This works in most cases, but the devils are always in\ndetails.  \"MODULE\" is defined when the target code (i.e. the sound\ncore) is built as a module; but this doesn\u0027t mean that the caller is\nalso built-in or not.  Namely, when only the sound core is built-in\n(CONFIG_SND=y) while the driver is a module (CONFIG_SND_USB_AUDIO=m),\nthe passed module pointer is ignored even if it\u0027s non-NULL, and\ncard-\u003emodule remains as NULL.  This would result in the missing module\nreference up/down at the device open/close, leading to a race with the\ncode execution after the module removal.\n\nFor addressing the bug, move the assignment of card-\u003emodule again out\nof ifdef.  The WARN_ON() is still wrapped with ifdef because the\nmodule can be really NULL when all sound drivers are built-in.\n\nNote that we keep \u0027ifdef MODULE\u0027 for WARN_ON(), otherwise it would\nlead to a false-positive NULL module check.  Admittedly it won\u0027t catch\nperfectly, i.e. no check is performed when CONFIG_SND=y.  But, it\u0027s no\nreal problem as it\u0027s only for debugging, and the condition is pretty\nrare."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - Exploitation requires opening a local ALSA device node (/dev/snd/pcmC*D*, controlC*, hwC*D*, timer, or an OSS/proc equivalent); there is no network-reachable path into snd_card_init or the affected open handlers.\nAC:L - The affected configuration (CONFIG_SND=y with a driver built as a module) is a shipped mainline defconfig, and the attacker deterministically creates the dangling state simply by holding an fd open \u2014 no memory-layout luck or unwinnable race is needed for the stale function-pointer call on release.\nPR:L - Only ordinary access to /dev/snd is needed, which is granted to the logged-in local user via session ACLs or the audio group on desktops and to the audio/media UID on Android \u2014 no capability is required to open the device and defeat the module-reference interlock.\nUI:N - No victim must be tricked into any action; the module removal that triggers the use-after-free occurs autonomously during routine driver updates, power-management, and hotplug scripts, and the attacker\u0027s own open() is what removes the safety interlock.\nS:U - The corruption and its consequences are confined to the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The card, substream, kcontrol and hwdep objects retain pointers into freed module text and data, so reads through those stale pointers disclose whatever now occupies the reclaimed module region, and a use-after-free of this class is leverageable into arbitrary kernel memory disclosure.\nI:H - Release and teardown perform indirect calls through substream-\u003eops and card-\u003eprivate_free into freed module memory that can be reallocated with attacker-influenced content, yielding a control-flow hijack primitive rather than a simple fault.\nA:H - Even without weaponization, dereferencing freed module text on close reliably oopses or panics the kernel, and the attacker can arrange this repeatedly."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:33:05.452Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/d7ff29a429b56f04783152ad7bbd7233b740e434"
            },
            {
              "url": "https://git.kernel.org/stable/c/e7e0ca200772bdb2fdc6d43d32d341e87a36f811"
            },
            {
              "url": "https://git.kernel.org/stable/c/e007476725730c1a68387b54b7629486d8a8301e"
            },
            {
              "url": "https://git.kernel.org/stable/c/e644036a3e2b2c9b3eee3c61b5d31c2ca8b5ba92"
            },
            {
              "url": "https://git.kernel.org/stable/c/c935e72139e6d523defd60fe875c01eb1f9ea5c5"
            },
            {
              "url": "https://git.kernel.org/stable/c/6b8374ee2cabcf034faa34e69a855dc496a9ec12"
            },
            {
              "url": "https://git.kernel.org/stable/c/39381fe7394e5eafac76e7e9367e7351138a29c1"
            }
          ],
          "title": "ALSA: core: Fix NULL module pointer assignment at card init",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-38605",
        "datePublished": "2024-06-19T13:48:15.769Z",
        "dateReserved": "2024-06-18T19:36:34.934Z",
        "dateUpdated": "2026-08-05T11:33:05.452Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-38573 (GCVE-0-2024-38573)

    Vulnerability from cvelistv5 – Published: 2024-06-19 13:35 – Updated: 2026-05-11 20:19
    VLAI
    Title
    cppc_cpufreq: Fix possible null pointer dereference
    Summary
    In the Linux kernel, the following vulnerability has been resolved: cppc_cpufreq: Fix possible null pointer dereference cppc_cpufreq_get_rate() and hisi_cppc_cpufreq_get_rate() can be called from different places with various parameters. So cpufreq_cpu_get() can return null as 'policy' in some circumstances. Fix this bug by adding null return check. Found by Linux Verification Center (linuxtesting.org) with SVACE.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-27 18:10 UTC
    CWE
    • CWE-476 - NULL Pointer Dereference
    Impacted products
    Vendor Product Version
    Linux Linux Affected: a28b2bfc099c6b9caa6ef697660408e076a32019 , < 9a185cc5a79ba408e1c73375706630662304f618 (git)
    Affected: a28b2bfc099c6b9caa6ef697660408e076a32019 , < 769c4f355b7962895205b86ad35617873feef9a5 (git)
    Affected: a28b2bfc099c6b9caa6ef697660408e076a32019 , < f84b9b25d045e67a7eee5e73f21278c8ab06713c (git)
    Affected: a28b2bfc099c6b9caa6ef697660408e076a32019 , < b18daa4ec727c0266de5bfc78e818d168cc4aedf (git)
    Affected: a28b2bfc099c6b9caa6ef697660408e076a32019 , < dfec15222529d22b15e5b0d63572a9e39570cab4 (git)
    Affected: a28b2bfc099c6b9caa6ef697660408e076a32019 , < cf7de25878a1f4508c69dc9f6819c21ba177dbfe (git)
    Create a notification for this product.
    Linux Linux Affected: 5.11
    Unaffected: 0 , < 5.11 (semver)
    Unaffected: 5.15.161 , ≤ 5.15.* (semver)
    Unaffected: 6.1.93 , ≤ 6.1.* (semver)
    Unaffected: 6.6.33 , ≤ 6.6.* (semver)
    Unaffected: 6.8.12 , ≤ 6.8.* (semver)
    Unaffected: 6.9.3 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: a28b2bfc099c , < 9a185cc5a79b (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: a28b2bfc099c , < 769c4f355b79 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: a28b2bfc099c , < f84b9b25d045 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: a28b2bfc099c , < b18daa4ec727 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: a28b2bfc099c , < dfec15222529 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux acrn Affected: a28b2bfc099c , < cf7de25878a1 (custom)
        cpe:2.3:o:linux:acrn:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 5.11
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 5.11 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.15.161 , ≤ 5.16 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.1.93 , ≤ 6.2 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.33 , ≤ 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.8.12 , ≤ 6.9 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9.3 , ≤ 6.10 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.10-rc1
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "9a185cc5a79b",
                    "status": "affected",
                    "version": "a28b2bfc099c",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "769c4f355b79",
                    "status": "affected",
                    "version": "a28b2bfc099c",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "f84b9b25d045",
                    "status": "affected",
                    "version": "a28b2bfc099c",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "b18daa4ec727",
                    "status": "affected",
                    "version": "a28b2bfc099c",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "dfec15222529",
                    "status": "affected",
                    "version": "a28b2bfc099c",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:acrn:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "acrn",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "cf7de25878a1",
                    "status": "affected",
                    "version": "a28b2bfc099c",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.11"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.11",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "5.16",
                    "status": "unaffected",
                    "version": "5.15.161",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.2",
                    "status": "unaffected",
                    "version": "6.1.93",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.7",
                    "status": "unaffected",
                    "version": "6.6.33",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.9",
                    "status": "unaffected",
                    "version": "6.8.12",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.10",
                    "status": "unaffected",
                    "version": "6.9.3",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.10-rc1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-38573",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-27T18:10:54.548059Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-476",
                    "description": "CWE-476 NULL Pointer Dereference",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-27T18:33:09.094Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T04:12:26.068Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/9a185cc5a79ba408e1c73375706630662304f618"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/769c4f355b7962895205b86ad35617873feef9a5"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/f84b9b25d045e67a7eee5e73f21278c8ab06713c"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/b18daa4ec727c0266de5bfc78e818d168cc4aedf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/dfec15222529d22b15e5b0d63572a9e39570cab4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/cf7de25878a1f4508c69dc9f6819c21ba177dbfe"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/cpufreq/cppc_cpufreq.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "9a185cc5a79ba408e1c73375706630662304f618",
                  "status": "affected",
                  "version": "a28b2bfc099c6b9caa6ef697660408e076a32019",
                  "versionType": "git"
                },
                {
                  "lessThan": "769c4f355b7962895205b86ad35617873feef9a5",
                  "status": "affected",
                  "version": "a28b2bfc099c6b9caa6ef697660408e076a32019",
                  "versionType": "git"
                },
                {
                  "lessThan": "f84b9b25d045e67a7eee5e73f21278c8ab06713c",
                  "status": "affected",
                  "version": "a28b2bfc099c6b9caa6ef697660408e076a32019",
                  "versionType": "git"
                },
                {
                  "lessThan": "b18daa4ec727c0266de5bfc78e818d168cc4aedf",
                  "status": "affected",
                  "version": "a28b2bfc099c6b9caa6ef697660408e076a32019",
                  "versionType": "git"
                },
                {
                  "lessThan": "dfec15222529d22b15e5b0d63572a9e39570cab4",
                  "status": "affected",
                  "version": "a28b2bfc099c6b9caa6ef697660408e076a32019",
                  "versionType": "git"
                },
                {
                  "lessThan": "cf7de25878a1f4508c69dc9f6819c21ba177dbfe",
                  "status": "affected",
                  "version": "a28b2bfc099c6b9caa6ef697660408e076a32019",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/cpufreq/cppc_cpufreq.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.11"
                },
                {
                  "lessThan": "5.11",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.161",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.93",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.33",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.12",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.161",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.93",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.33",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.12",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.3",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "5.11",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncppc_cpufreq: Fix possible null pointer dereference\n\ncppc_cpufreq_get_rate() and hisi_cppc_cpufreq_get_rate() can be called from\ndifferent places with various parameters. So cpufreq_cpu_get() can return\nnull as \u0027policy\u0027 in some circumstances.\nFix this bug by adding null return check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T20:19:19.668Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/9a185cc5a79ba408e1c73375706630662304f618"
            },
            {
              "url": "https://git.kernel.org/stable/c/769c4f355b7962895205b86ad35617873feef9a5"
            },
            {
              "url": "https://git.kernel.org/stable/c/f84b9b25d045e67a7eee5e73f21278c8ab06713c"
            },
            {
              "url": "https://git.kernel.org/stable/c/b18daa4ec727c0266de5bfc78e818d168cc4aedf"
            },
            {
              "url": "https://git.kernel.org/stable/c/dfec15222529d22b15e5b0d63572a9e39570cab4"
            },
            {
              "url": "https://git.kernel.org/stable/c/cf7de25878a1f4508c69dc9f6819c21ba177dbfe"
            }
          ],
          "title": "cppc_cpufreq: Fix possible null pointer dereference",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-38573",
        "datePublished": "2024-06-19T13:35:38.334Z",
        "dateReserved": "2024-06-18T19:36:34.924Z",
        "dateUpdated": "2026-05-11T20:19:19.668Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-38541 (GCVE-0-2024-38541)

    Vulnerability from cvelistv5 – Published: 2024-06-19 13:35 – Updated: 2026-08-05 11:32
    VLAI
    Title
    of: module: add buffer overflow check in of_modalias()
    Summary
    In the Linux kernel, the following vulnerability has been resolved: of: module: add buffer overflow check in of_modalias() In of_modalias(), if the buffer happens to be too small even for the 1st snprintf() call, the len parameter will become negative and str parameter (if not NULL initially) will point beyond the buffer's end. Add the buffer overflow check after the 1st snprintf() call and fix such check after the strlen() call (accounting for the terminating NUL char).
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-07 19:51 UTC
    CWE
    • CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
    Impacted products
    Vendor Product Version
    Linux Linux Affected: bc575064d688c8933a6ca51429bea9bc63628d3b , < 46795440ef2b4ac919d09310a69a404c5bc90a88 (git)
    Affected: bc575064d688c8933a6ca51429bea9bc63628d3b , < 733e62786bdf1b2b9dbb09ba2246313306503414 (git)
    Affected: bc575064d688c8933a6ca51429bea9bc63628d3b , < c7f24b7d94549ff4623e8f41ea4d9f5319bd8ac8 (git)
    Affected: bc575064d688c8933a6ca51429bea9bc63628d3b , < 5d59fd637a8af42b211a92b2edb2474325b4d488 (git)
    Affected: bc575064d688c8933a6ca51429bea9bc63628d3b , < 0b0d5701a8bf02f8fee037e81aacf6746558bfd6 (git)
    Affected: bc575064d688c8933a6ca51429bea9bc63628d3b , < ee332023adfd5882808f2dabf037b32d6ce36f9e (git)
    Affected: bc575064d688c8933a6ca51429bea9bc63628d3b , < e45b69360a63165377b30db4a1dfddd89ca18e9a (git)
    Affected: bc575064d688c8933a6ca51429bea9bc63628d3b , < cf7385cb26ac4f0ee6c7385960525ad534323252 (git)
    Create a notification for this product.
    Linux Linux Affected: 4.14
    Unaffected: 0 , < 4.14 (semver)
    Unaffected: 5.4.294 , ≤ 5.4.* (semver)
    Unaffected: 5.10.238 , ≤ 5.10.* (semver)
    Unaffected: 5.15.182 , ≤ 5.15.* (semver)
    Unaffected: 6.1.136 , ≤ 6.1.* (semver)
    Unaffected: 6.6.33 , ≤ 6.6.* (semver)
    Unaffected: 6.8.12 , ≤ 6.8.* (semver)
    Unaffected: 6.9.3 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: bc575064d688 , < 0b0d5701a8bf (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: bc575064d688 , < ee332023adfd (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: bc575064d688 , < e45b69360a63 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: bc575064d688 , < cf7385cb26ac (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 4.14
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 4.14 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.33 , ≤ 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.8.12 , ≤ 6.9 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9.3 , ≤ 6.10 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.10-rc1
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "0b0d5701a8bf",
                    "status": "affected",
                    "version": "bc575064d688",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "ee332023adfd",
                    "status": "affected",
                    "version": "bc575064d688",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "e45b69360a63",
                    "status": "affected",
                    "version": "bc575064d688",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "cf7385cb26ac",
                    "status": "affected",
                    "version": "bc575064d688",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.14"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "4.14",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.7",
                    "status": "unaffected",
                    "version": "6.6.33",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.9",
                    "status": "unaffected",
                    "version": "6.8.12",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.10",
                    "status": "unaffected",
                    "version": "6.9.3",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.10-rc1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-38541",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-07T19:51:57.578646Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-120",
                    "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-04T13:56:15.426Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:30:14.802Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/0b0d5701a8bf02f8fee037e81aacf6746558bfd6"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/ee332023adfd5882808f2dabf037b32d6ce36f9e"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/e45b69360a63165377b30db4a1dfddd89ca18e9a"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/cf7385cb26ac4f0ee6c7385960525ad534323252"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/of/module.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "46795440ef2b4ac919d09310a69a404c5bc90a88",
                  "status": "affected",
                  "version": "bc575064d688c8933a6ca51429bea9bc63628d3b",
                  "versionType": "git"
                },
                {
                  "lessThan": "733e62786bdf1b2b9dbb09ba2246313306503414",
                  "status": "affected",
                  "version": "bc575064d688c8933a6ca51429bea9bc63628d3b",
                  "versionType": "git"
                },
                {
                  "lessThan": "c7f24b7d94549ff4623e8f41ea4d9f5319bd8ac8",
                  "status": "affected",
                  "version": "bc575064d688c8933a6ca51429bea9bc63628d3b",
                  "versionType": "git"
                },
                {
                  "lessThan": "5d59fd637a8af42b211a92b2edb2474325b4d488",
                  "status": "affected",
                  "version": "bc575064d688c8933a6ca51429bea9bc63628d3b",
                  "versionType": "git"
                },
                {
                  "lessThan": "0b0d5701a8bf02f8fee037e81aacf6746558bfd6",
                  "status": "affected",
                  "version": "bc575064d688c8933a6ca51429bea9bc63628d3b",
                  "versionType": "git"
                },
                {
                  "lessThan": "ee332023adfd5882808f2dabf037b32d6ce36f9e",
                  "status": "affected",
                  "version": "bc575064d688c8933a6ca51429bea9bc63628d3b",
                  "versionType": "git"
                },
                {
                  "lessThan": "e45b69360a63165377b30db4a1dfddd89ca18e9a",
                  "status": "affected",
                  "version": "bc575064d688c8933a6ca51429bea9bc63628d3b",
                  "versionType": "git"
                },
                {
                  "lessThan": "cf7385cb26ac4f0ee6c7385960525ad534323252",
                  "status": "affected",
                  "version": "bc575064d688c8933a6ca51429bea9bc63628d3b",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/of/module.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.14"
                },
                {
                  "lessThan": "4.14",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.294",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.238",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.182",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.136",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.33",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.12",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.294",
                      "versionStartIncluding": "4.14",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.238",
                      "versionStartIncluding": "4.14",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.182",
                      "versionStartIncluding": "4.14",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.136",
                      "versionStartIncluding": "4.14",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.33",
                      "versionStartIncluding": "4.14",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.12",
                      "versionStartIncluding": "4.14",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.3",
                      "versionStartIncluding": "4.14",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "4.14",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nof: module: add buffer overflow check in of_modalias()\n\nIn of_modalias(), if the buffer happens to be too small even for the 1st\nsnprintf() call, the len parameter will become negative and str parameter\n(if not NULL initially) will point beyond the buffer\u0027s end. Add the buffer\noverflow check after the 1st snprintf() call and fix such check after the\nstrlen() call (accounting for the terminating NUL char)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - `of_modalias()` is reached only through local syscalls \u2014 `read()` on the world-readable `uevent` (0644) or `modalias` (0444) sysfs attributes of any device-tree-backed device. No network protocol handler parses attacker data into this function.\nAC:L - The attacker simply reads a sysfs file; the code path is deterministic, repeatable, and involves no race, no memory-layout grooming, and no condition that must happen to occur at exploit time. Whether a qualifying DT node exists is a static property of the target platform, which CVSS treats as target configuration rather than attack complexity.\nPR:L - Any unprivileged local account can read `/sys/devices/.../uevent` and `/sys/devices/.../modalias`, which are mode 0644 and 0444 respectively \u2014 no capability, no user namespace, and no root is required.\nUI:N - The attacker triggers the code path entirely on their own by reading a sysfs attribute; no victim needs to mount a filesystem, plug in a device, or take any other action.\nS:U - The defect and its consequences are confined to the kernel\u0027s own address space and security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The write cursor is advanced past the end of the caller\u0027s buffer while the length accounting goes negative, and the loop guard omits the NUL terminator \u2014 out-of-bounds accounting adjacent to a heap-allocated `kobj_uevent_env` that is subsequently copied straight back to userspace, which can expose adjacent kernel heap contents.\nI:H - The commit adds an explicit buffer overflow check because `str` is left pointing beyond the buffer\u0027s end with a corrupted remaining-length value; out-of-bounds write accounting on a kernel heap buffer is scored High per out-of-bounds-write guidance.\nA:H - Corrupting memory past the end of a `kmalloc`\u0027d uevent buffer can smash adjacent slab objects or redzones, producing a kernel oops or panic, and the path can be re-triggered arbitrarily often by an unprivileged reader."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:32:39.656Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/46795440ef2b4ac919d09310a69a404c5bc90a88"
            },
            {
              "url": "https://git.kernel.org/stable/c/733e62786bdf1b2b9dbb09ba2246313306503414"
            },
            {
              "url": "https://git.kernel.org/stable/c/c7f24b7d94549ff4623e8f41ea4d9f5319bd8ac8"
            },
            {
              "url": "https://git.kernel.org/stable/c/5d59fd637a8af42b211a92b2edb2474325b4d488"
            },
            {
              "url": "https://git.kernel.org/stable/c/0b0d5701a8bf02f8fee037e81aacf6746558bfd6"
            },
            {
              "url": "https://git.kernel.org/stable/c/ee332023adfd5882808f2dabf037b32d6ce36f9e"
            },
            {
              "url": "https://git.kernel.org/stable/c/e45b69360a63165377b30db4a1dfddd89ca18e9a"
            },
            {
              "url": "https://git.kernel.org/stable/c/cf7385cb26ac4f0ee6c7385960525ad534323252"
            }
          ],
          "title": "of: module: add buffer overflow check in of_modalias()",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-38541",
        "datePublished": "2024-06-19T13:35:16.637Z",
        "dateReserved": "2024-06-18T19:36:34.919Z",
        "dateUpdated": "2026-08-05T11:32:39.656Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-36972 (GCVE-0-2024-36972)

    Vulnerability from cvelistv5 – Published: 2024-06-10 14:57 – Updated: 2026-08-05 11:32
    VLAI
    Title
    af_unix: Update unix_sk(sk)->oob_skb under sk_receive_queue lock.
    Summary
    In the Linux kernel, the following vulnerability has been resolved: af_unix: Update unix_sk(sk)->oob_skb under sk_receive_queue lock. Billy Jheng Bing-Jhong reported a race between __unix_gc() and queue_oob(). __unix_gc() tries to garbage-collect close()d inflight sockets, and then if the socket has MSG_OOB in unix_sk(sk)->oob_skb, GC will drop the reference and set NULL to it locklessly. However, the peer socket still can send MSG_OOB message and queue_oob() can update unix_sk(sk)->oob_skb concurrently, leading NULL pointer dereference. [0] To fix the issue, let's update unix_sk(sk)->oob_skb under the sk_receive_queue's lock and take it everywhere we touch oob_skb. Note that we defer kfree_skb() in manage_oob() to silence lockdep false-positive (See [1]). [0]: BUG: kernel NULL pointer dereference, address: 0000000000000008 PF: supervisor write access in kernel mode PF: error_code(0x0002) - not-present page PGD 8000000009f5e067 P4D 8000000009f5e067 PUD 9f5d067 PMD 0 Oops: 0002 [#1] PREEMPT SMP PTI CPU: 3 PID: 50 Comm: kworker/3:1 Not tainted 6.9.0-rc5-00191-gd091e579b864 #110 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 Workqueue: events delayed_fput RIP: 0010:skb_dequeue (./include/linux/skbuff.h:2386 ./include/linux/skbuff.h:2402 net/core/skbuff.c:3847) Code: 39 e3 74 3e 8b 43 10 48 89 ef 83 e8 01 89 43 10 49 8b 44 24 08 49 c7 44 24 08 00 00 00 00 49 8b 14 24 49 c7 04 24 00 00 00 00 <48> 89 42 08 48 89 10 e8 e7 c5 42 00 4c 89 e0 5b 5d 41 5c c3 cc cc RSP: 0018:ffffc900001bfd48 EFLAGS: 00000002 RAX: 0000000000000000 RBX: ffff8880088f5ae8 RCX: 00000000361289f9 RDX: 0000000000000000 RSI: 0000000000000206 RDI: ffff8880088f5b00 RBP: ffff8880088f5b00 R08: 0000000000080000 R09: 0000000000000001 R10: 0000000000000003 R11: 0000000000000001 R12: ffff8880056b6a00 R13: ffff8880088f5280 R14: 0000000000000001 R15: ffff8880088f5a80 FS: 0000000000000000(0000) GS:ffff88807dd80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000008 CR3: 0000000006314000 CR4: 00000000007506f0 PKRU: 55555554 Call Trace: <TASK> unix_release_sock (net/unix/af_unix.c:654) unix_release (net/unix/af_unix.c:1050) __sock_release (net/socket.c:660) sock_close (net/socket.c:1423) __fput (fs/file_table.c:423) delayed_fput (fs/file_table.c:444 (discriminator 3)) process_one_work (kernel/workqueue.c:3259) worker_thread (kernel/workqueue.c:3329 kernel/workqueue.c:3416) kthread (kernel/kthread.c:388) ret_from_fork (arch/x86/kernel/process.c:153) ret_from_fork_asm (arch/x86/entry/entry_64.S:257) </TASK> Modules linked in: CR2: 0000000000000008
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-05 03:56 UTC
    CWE
    • CWE-476 - NULL Pointer Dereference
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 4fe505c63aa3273135a57597fda761e9aecc7668 , < 518a994aa0b87d96f1bc6678a7035df5d1fcd7a1 (git)
    Affected: e0e09186d8821ad59806115d347ea32efa43ca4b , < 4bf6964451c3cb411fbaa1ae8b214b3d97a59bf1 (git)
    Affected: b74aa9ce13d02b7fd37c5325b99854f91b9b4276 , < d59ae9314b97e01c76a4171472441e55721ba636 (git)
    Affected: 1279f9d9dec2d7462823a18c29ad61359e0a007d , < 4708f49add84a57ce0ccc7bf9a6269845c631cc3 (git)
    Affected: 1279f9d9dec2d7462823a18c29ad61359e0a007d , < 9841991a446c87f90f66f4b9fee6fe934c1336a2 (git)
    Affected: 82ae47c5c3a6b27fdc0f9e83c1499cb439c56140 (git)
    Affected: 5.15.149 , < 5.15.161 (semver)
    Affected: 6.1.78 , < 6.1.93 (semver)
    Affected: 6.6.17 , < 6.6.33 (semver)
    Affected: 6.7.5 , < 6.8 (semver)
    Create a notification for this product.
    Linux Linux Affected: 6.8
    Unaffected: 0 , < 6.8 (semver)
    Unaffected: 5.15.161 , ≤ 5.15.* (semver)
    Unaffected: 6.1.93 , ≤ 6.1.* (semver)
    Unaffected: 6.6.33 , ≤ 6.6.* (semver)
    Unaffected: 6.9.4 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 4fe505c63aa3 , < 518a994aa0b8 (git)
    Affected: e0e09186d882 , < 4bf6964451c3 (git)
    Affected: b74aa9ce13d0 , < d59ae9314b97 (custom)
    Affected: 1279f9d9dec2 , < 4708f49add84 (custom)
    Affected: 1279f9d9dec2 , < 9841991a446c (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 6.8
        cpe:2.3:o:linux:linux_kernel:6.8:-:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "518a994aa0b8",
                    "status": "affected",
                    "version": "4fe505c63aa3",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "4bf6964451c3",
                    "status": "affected",
                    "version": "e0e09186d882",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "d59ae9314b97",
                    "status": "affected",
                    "version": "b74aa9ce13d0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4708f49add84",
                    "status": "affected",
                    "version": "1279f9d9dec2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "9841991a446c",
                    "status": "affected",
                    "version": "1279f9d9dec2",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:6.8:-:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.8"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-36972",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-05T03:56:02.065864Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-476",
                    "description": "CWE-476 NULL Pointer Dereference",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-05T15:34:54.248Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T03:43:50.584Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/518a994aa0b87d96f1bc6678a7035df5d1fcd7a1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/4bf6964451c3cb411fbaa1ae8b214b3d97a59bf1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/d59ae9314b97e01c76a4171472441e55721ba636"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/4708f49add84a57ce0ccc7bf9a6269845c631cc3"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/9841991a446c87f90f66f4b9fee6fe934c1336a2"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/unix/af_unix.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "518a994aa0b87d96f1bc6678a7035df5d1fcd7a1",
                  "status": "affected",
                  "version": "4fe505c63aa3273135a57597fda761e9aecc7668",
                  "versionType": "git"
                },
                {
                  "lessThan": "4bf6964451c3cb411fbaa1ae8b214b3d97a59bf1",
                  "status": "affected",
                  "version": "e0e09186d8821ad59806115d347ea32efa43ca4b",
                  "versionType": "git"
                },
                {
                  "lessThan": "d59ae9314b97e01c76a4171472441e55721ba636",
                  "status": "affected",
                  "version": "b74aa9ce13d02b7fd37c5325b99854f91b9b4276",
                  "versionType": "git"
                },
                {
                  "lessThan": "4708f49add84a57ce0ccc7bf9a6269845c631cc3",
                  "status": "affected",
                  "version": "1279f9d9dec2d7462823a18c29ad61359e0a007d",
                  "versionType": "git"
                },
                {
                  "lessThan": "9841991a446c87f90f66f4b9fee6fe934c1336a2",
                  "status": "affected",
                  "version": "1279f9d9dec2d7462823a18c29ad61359e0a007d",
                  "versionType": "git"
                },
                {
                  "status": "affected",
                  "version": "82ae47c5c3a6b27fdc0f9e83c1499cb439c56140",
                  "versionType": "git"
                },
                {
                  "lessThan": "5.15.161",
                  "status": "affected",
                  "version": "5.15.149",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.1.93",
                  "status": "affected",
                  "version": "6.1.78",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.6.33",
                  "status": "affected",
                  "version": "6.6.17",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.8",
                  "status": "affected",
                  "version": "6.7.5",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/unix/af_unix.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.8"
                },
                {
                  "lessThan": "6.8",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.161",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.93",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.33",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.161",
                      "versionStartIncluding": "5.15.149",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.93",
                      "versionStartIncluding": "6.1.78",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.33",
                      "versionStartIncluding": "6.6.17",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.4",
                      "versionStartIncluding": "6.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "6.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionStartIncluding": "6.7.5",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Update unix_sk(sk)-\u003eoob_skb under sk_receive_queue lock.\n\nBilly Jheng Bing-Jhong reported a race between __unix_gc() and\nqueue_oob().\n\n__unix_gc() tries to garbage-collect close()d inflight sockets,\nand then if the socket has MSG_OOB in unix_sk(sk)-\u003eoob_skb, GC\nwill drop the reference and set NULL to it locklessly.\n\nHowever, the peer socket still can send MSG_OOB message and\nqueue_oob() can update unix_sk(sk)-\u003eoob_skb concurrently, leading\nNULL pointer dereference. [0]\n\nTo fix the issue, let\u0027s update unix_sk(sk)-\u003eoob_skb under the\nsk_receive_queue\u0027s lock and take it everywhere we touch oob_skb.\n\nNote that we defer kfree_skb() in manage_oob() to silence lockdep\nfalse-positive (See [1]).\n\n[0]:\nBUG: kernel NULL pointer dereference, address: 0000000000000008\n PF: supervisor write access in kernel mode\n PF: error_code(0x0002) - not-present page\nPGD 8000000009f5e067 P4D 8000000009f5e067 PUD 9f5d067 PMD 0\nOops: 0002 [#1] PREEMPT SMP PTI\nCPU: 3 PID: 50 Comm: kworker/3:1 Not tainted 6.9.0-rc5-00191-gd091e579b864 #110\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\nWorkqueue: events delayed_fput\nRIP: 0010:skb_dequeue (./include/linux/skbuff.h:2386 ./include/linux/skbuff.h:2402 net/core/skbuff.c:3847)\nCode: 39 e3 74 3e 8b 43 10 48 89 ef 83 e8 01 89 43 10 49 8b 44 24 08 49 c7 44 24 08 00 00 00 00 49 8b 14 24 49 c7 04 24 00 00 00 00 \u003c48\u003e 89 42 08 48 89 10 e8 e7 c5 42 00 4c 89 e0 5b 5d 41 5c c3 cc cc\nRSP: 0018:ffffc900001bfd48 EFLAGS: 00000002\nRAX: 0000000000000000 RBX: ffff8880088f5ae8 RCX: 00000000361289f9\nRDX: 0000000000000000 RSI: 0000000000000206 RDI: ffff8880088f5b00\nRBP: ffff8880088f5b00 R08: 0000000000080000 R09: 0000000000000001\nR10: 0000000000000003 R11: 0000000000000001 R12: ffff8880056b6a00\nR13: ffff8880088f5280 R14: 0000000000000001 R15: ffff8880088f5a80\nFS:  0000000000000000(0000) GS:ffff88807dd80000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000008 CR3: 0000000006314000 CR4: 00000000007506f0\nPKRU: 55555554\nCall Trace:\n \u003cTASK\u003e\n unix_release_sock (net/unix/af_unix.c:654)\n unix_release (net/unix/af_unix.c:1050)\n __sock_release (net/socket.c:660)\n sock_close (net/socket.c:1423)\n __fput (fs/file_table.c:423)\n delayed_fput (fs/file_table.c:444 (discriminator 3))\n process_one_work (kernel/workqueue.c:3259)\n worker_thread (kernel/workqueue.c:3329 kernel/workqueue.c:3416)\n kthread (kernel/kthread.c:388)\n ret_from_fork (arch/x86/kernel/process.c:153)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:257)\n \u003c/TASK\u003e\nModules linked in:\nCR2: 0000000000000008"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - AF_UNIX is local-only IPC; the race is driven from `sendmsg(MSG_OOB)` and `close()` syscalls on socketpairs, with no network-facing entry point.\nAC:L - The attacker controls both sides of the race \u2014 it queues MSG_OOB in a loop on one CPU while forcing `unix_gc()` on another by closing sockets with inflight SCM_RIGHTS cycles, and can retry indefinitely until the window is hit.\nPR:L - Any unprivileged local user can create AF_UNIX socketpairs, send MSG_OOB and SCM_RIGHTS, and close descriptors; no capabilities, namespaces, or non-default configuration are required (CONFIG_AF_UNIX_OOB is default y).\nUI:N - The attacker performs every step itself from its own processes/threads; no victim action or cooperating peer is needed since a socketpair is self-owned.\nS:U - The corruption is confined to kernel memory within the same security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - The double-free leaves a freed sk_buff linked in `sk_receive_queue`; reclaiming it with sprayed data lets the attacker control `skb-\u003edata`/`skb-\u003elen` and read arbitrary kernel memory via subsequent recvmsg.\nI:H - A use-after-free/double-free of an sk_buff yields write primitives (list unlink writes and attacker-controlled skb fields on reclaimed slab objects), which is exploitable for privilege escalation.\nA:H - The reported symptom is a kernel oops (supervisor write fault in `skb_dequeue` from `unix_release_sock`), and freed-object list corruption reliably panics the machine."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:32:23.250Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/518a994aa0b87d96f1bc6678a7035df5d1fcd7a1"
            },
            {
              "url": "https://git.kernel.org/stable/c/4bf6964451c3cb411fbaa1ae8b214b3d97a59bf1"
            },
            {
              "url": "https://git.kernel.org/stable/c/d59ae9314b97e01c76a4171472441e55721ba636"
            },
            {
              "url": "https://git.kernel.org/stable/c/4708f49add84a57ce0ccc7bf9a6269845c631cc3"
            },
            {
              "url": "https://git.kernel.org/stable/c/9841991a446c87f90f66f4b9fee6fe934c1336a2"
            }
          ],
          "title": "af_unix: Update unix_sk(sk)-\u003eoob_skb under sk_receive_queue lock.",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-36972",
        "datePublished": "2024-06-10T14:57:42.271Z",
        "dateReserved": "2024-05-30T15:25:07.082Z",
        "dateUpdated": "2026-08-05T11:32:23.250Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-36971 (GCVE-0-2024-36971)

    Vulnerability from cvelistv5 – Published: 2024-06-10 09:03 – Updated: 2026-08-05 11:32
    VLAI
    Title
    net: fix __dst_negative_advice() race
    Summary
    In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear sk->sk_dst_cache, then call dst_release(old_dst). Note that sk_dst_reset(sk) is implementing this protocol correctly, while __dst_negative_advice() uses the wrong order. Given that ip6_negative_advice() has special logic against RTF_CACHE, this means each of the three ->negative_advice() existing methods must perform the sk_dst_reset() themselves. Note the check against NULL dst is centralized in __dst_negative_advice(), there is no need to duplicate it in various callbacks. Many thanks to Clement Lecigne for tracking this issue. This old bug became visible after the blamed commit, using UDP sockets.
    SSVC
    Exploitation: active Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-08 03:55 UTC
    CWE
    Impacted products
    Vendor Product Version
    Linux Linux Affected: a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314 , < 051c0bde9f0450a2ec3d62a86d2a0d2fad117f13 (git)
    Affected: a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314 , < db0082825037794c5dba9959c9de13ca34cc5e72 (git)
    Affected: a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314 , < 2295a7ef5c8c49241bff769e7826ef2582e532a6 (git)
    Affected: a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314 , < eacb8b195579c174a6d3e12a9690b206eb7f28cf (git)
    Affected: a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314 , < 81dd3c82a456b0015461754be7cb2693991421b4 (git)
    Affected: a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314 , < 5af198c387128a9d2ddd620b0f0803564a4d4508 (git)
    Affected: a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314 , < b8af8e6118a6605f0e495a58d591ca94a85a50fc (git)
    Affected: a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314 , < 92f1655aa2b2294d0b49925f3b875a634bd3b59e (git)
    Create a notification for this product.
    Linux Linux Affected: 4.6
    Unaffected: 0 , < 4.6 (semver)
    Unaffected: 4.19.316 , ≤ 4.19.* (semver)
    Unaffected: 5.4.278 , ≤ 5.4.* (semver)
    Unaffected: 5.10.219 , ≤ 5.10.* (semver)
    Unaffected: 5.15.161 , ≤ 5.15.* (semver)
    Unaffected: 6.1.94 , ≤ 6.1.* (semver)
    Unaffected: 6.6.34 , ≤ 6.6.* (semver)
    Unaffected: 6.9.4 , ≤ 6.9.* (semver)
    Unaffected: 6.10 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 4.6
        cpe:2.3:o:linux:linux_kernel:4.6:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: a87cb3e48ee8 , < 051c0bde9f04 (git)
    Affected: a87cb3e48ee8 , < db0082825037 (git)
    Affected: a87cb3e48ee8 , < 2295a7ef5c8c (git)
    Affected: a87cb3e48ee8 , < eacb8b195579 (git)
    Affected: a87cb3e48ee8 , < 81dd3c82a456 (git)
    Affected: a87cb3e48ee8 , < 5af198c38712 (git)
    Affected: a87cb3e48ee8 , < b8af8e6118a6 (git)
    Affected: a87cb3e48ee8 , < 92f1655aa2b2 (git)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 4.6 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 4.19.316 , < 4.20 (custom)
        cpe:2.3:o:linux:linux_kernel:4.19.316:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.4.278 , < 5.5 (custom)
        cpe:2.3:o:linux:linux_kernel:5.4.278:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.10.219 , < 5.11 (custom)
        cpe:2.3:o:linux:linux_kernel:5.10.219:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.15.161 , < 5.16 (custom)
        cpe:2.3:o:linux:linux_kernel:5.15.161:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.1.94 , < 6.2 (custom)
        cpe:2.3:o:linux:linux_kernel:6.1.94:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.34 , < 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:6.6.34:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9.4 , < 6.10 (custom)
        cpe:2.3:o:linux:linux_kernel:6.9.4:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.10 , ≤ * (custom)
        cpe:2.3:o:linux:linux_kernel:6.10:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-04T17:21:17.010Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/051c0bde9f0450a2ec3d62a86d2a0d2fad117f13"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/db0082825037794c5dba9959c9de13ca34cc5e72"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/2295a7ef5c8c49241bff769e7826ef2582e532a6"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/eacb8b195579c174a6d3e12a9690b206eb7f28cf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/81dd3c82a456b0015461754be7cb2693991421b4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/5af198c387128a9d2ddd620b0f0803564a4d4508"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/b8af8e6118a6605f0e495a58d591ca94a85a50fc"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/92f1655aa2b2294d0b49925f3b875a634bd3b59e"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:4.6:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.6"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "051c0bde9f04",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "db0082825037",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "2295a7ef5c8c",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "eacb8b195579",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "81dd3c82a456",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5af198c38712",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b8af8e6118a6",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "92f1655aa2b2",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "051c0bde9f04",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "db0082825037",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "2295a7ef5c8c",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "eacb8b195579",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "81dd3c82a456",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5af198c38712",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b8af8e6118a6",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "92f1655aa2b2",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "051c0bde9f04",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "db0082825037",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "2295a7ef5c8c",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "eacb8b195579",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "81dd3c82a456",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5af198c38712",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b8af8e6118a6",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "92f1655aa2b2",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "051c0bde9f04",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "db0082825037",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "2295a7ef5c8c",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "eacb8b195579",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "81dd3c82a456",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5af198c38712",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b8af8e6118a6",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "92f1655aa2b2",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "051c0bde9f04",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "db0082825037",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "2295a7ef5c8c",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "eacb8b195579",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "81dd3c82a456",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5af198c38712",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b8af8e6118a6",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "92f1655aa2b2",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "051c0bde9f04",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "db0082825037",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "2295a7ef5c8c",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "eacb8b195579",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "81dd3c82a456",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5af198c38712",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b8af8e6118a6",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "92f1655aa2b2",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "051c0bde9f04",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "db0082825037",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "2295a7ef5c8c",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "eacb8b195579",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "81dd3c82a456",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5af198c38712",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b8af8e6118a6",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "92f1655aa2b2",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "051c0bde9f04",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "db0082825037",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "2295a7ef5c8c",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "eacb8b195579",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "81dd3c82a456",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5af198c38712",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b8af8e6118a6",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "92f1655aa2b2",
                    "status": "affected",
                    "version": "a87cb3e48ee8",
                    "versionType": "git"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "4.6",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:4.19.316:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "4.20",
                    "status": "unaffected",
                    "version": "4.19.316",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:5.4.278:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.5",
                    "status": "unaffected",
                    "version": "5.4.278",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:5.10.219:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.11",
                    "status": "unaffected",
                    "version": "5.10.219",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:5.15.161:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.16",
                    "status": "unaffected",
                    "version": "5.15.161",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:6.1.94:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.2",
                    "status": "unaffected",
                    "version": "6.1.94",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:6.6.34:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.7",
                    "status": "unaffected",
                    "version": "6.6.34",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:6.9.4:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.10",
                    "status": "unaffected",
                    "version": "6.9.4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:6.10:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "6.10",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-36971",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-08T03:55:25.565547Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2024-08-07",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-36971"
                  },
                  "type": "kev"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T22:56:22.761Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-36971"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2024-08-07T00:00:00.000Z",
                "value": "CVE-2024-36971 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "include/net/dst_ops.h",
                "include/net/sock.h",
                "net/ipv4/route.c",
                "net/ipv6/route.c",
                "net/xfrm/xfrm_policy.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "051c0bde9f0450a2ec3d62a86d2a0d2fad117f13",
                  "status": "affected",
                  "version": "a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314",
                  "versionType": "git"
                },
                {
                  "lessThan": "db0082825037794c5dba9959c9de13ca34cc5e72",
                  "status": "affected",
                  "version": "a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314",
                  "versionType": "git"
                },
                {
                  "lessThan": "2295a7ef5c8c49241bff769e7826ef2582e532a6",
                  "status": "affected",
                  "version": "a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314",
                  "versionType": "git"
                },
                {
                  "lessThan": "eacb8b195579c174a6d3e12a9690b206eb7f28cf",
                  "status": "affected",
                  "version": "a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314",
                  "versionType": "git"
                },
                {
                  "lessThan": "81dd3c82a456b0015461754be7cb2693991421b4",
                  "status": "affected",
                  "version": "a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314",
                  "versionType": "git"
                },
                {
                  "lessThan": "5af198c387128a9d2ddd620b0f0803564a4d4508",
                  "status": "affected",
                  "version": "a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314",
                  "versionType": "git"
                },
                {
                  "lessThan": "b8af8e6118a6605f0e495a58d591ca94a85a50fc",
                  "status": "affected",
                  "version": "a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314",
                  "versionType": "git"
                },
                {
                  "lessThan": "92f1655aa2b2294d0b49925f3b875a634bd3b59e",
                  "status": "affected",
                  "version": "a87cb3e48ee86d29868d3f59cfb9ce1a8fa63314",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "include/net/dst_ops.h",
                "include/net/sock.h",
                "net/ipv4/route.c",
                "net/ipv6/route.c",
                "net/xfrm/xfrm_policy.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.6"
                },
                {
                  "lessThan": "4.6",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "4.19.*",
                  "status": "unaffected",
                  "version": "4.19.316",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.278",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.219",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.161",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.94",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.34",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.9.*",
                  "status": "unaffected",
                  "version": "6.9.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.10",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.19.316",
                      "versionStartIncluding": "4.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.278",
                      "versionStartIncluding": "4.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.219",
                      "versionStartIncluding": "4.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.161",
                      "versionStartIncluding": "4.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.94",
                      "versionStartIncluding": "4.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.34",
                      "versionStartIncluding": "4.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.4",
                      "versionStartIncluding": "4.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.10",
                      "versionStartIncluding": "4.6",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix __dst_negative_advice() race\n\n__dst_negative_advice() does not enforce proper RCU rules when\nsk-\u003edst_cache must be cleared, leading to possible UAF.\n\nRCU rules are that we must first clear sk-\u003esk_dst_cache,\nthen call dst_release(old_dst).\n\nNote that sk_dst_reset(sk) is implementing this protocol correctly,\nwhile __dst_negative_advice() uses the wrong order.\n\nGiven that ip6_negative_advice() has special logic\nagainst RTF_CACHE, this means each of the three -\u003enegative_advice()\nexisting methods must perform the sk_dst_reset() themselves.\n\nNote the check against NULL dst is centralized in\n__dst_negative_advice(), there is no need to duplicate\nit in various callbacks.\n\nMany thanks to Clement Lecigne for tracking this issue.\n\nThis old bug became visible after the blamed commit, using UDP sockets."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The race must be driven by two concurrent local socket operations on the same fd \u2014 `setsockopt(SO_CNX_ADVICE)` and a lockless `udp_sendmsg()` \u2014 so the attacker needs local syscall access. A remote peer can drive only the free side (TCP retransmit timeouts, ICMP-induced PMTU/redirect exceptions), not the racing `sk_dst_cache` writer.\nAC:L - The attacker controls both sides of the race (one thread calling `SO_CNX_ADVICE`, another calling `sendmsg()` on the same connected socket) and can create the required route-exception/obsolete-dst precondition at will, retrying indefinitely across many sockets; in-the-wild exploitation confirms it is reliably winnable.\nPR:L - `SO_CNX_ADVICE` in `sock_setsockopt()` carries no capability check and a connected UDP socket needs no privileges, so any unprivileged local user \u2014 including a sandboxed Android app, as in the observed real-world exploit \u2014 can reach the code.\nUI:N - Exploitation is entirely self-driven through the attacker\u0027s own socket, timers and threads; no victim action is needed.\nS:U - The corrupted `dst_entry` and the resulting code execution are both within the kernel\u0027s own security authority \u2014 standard local privilege escalation, no VM/IOMMU boundary crossed.\nC:H - The refcount underflow yields a use-after-free on a `dst_entry` whose contents (ops table, metrics, neighbour and function pointers) can be replaced by attacker-sprayed data, giving a kernel read primitive and full disclosure once escalated to root.\nI:H - `dst_entry` holds `ops`, `input()` and `output()` function pointers invoked on every transmit, so reclaiming the freed object gives direct control-flow hijack and arbitrary kernel write \u2014 this was weaponized as an in-the-wild Android privilege escalation.\nA:H - Even unweaponized, the premature free and dangling `sk_dst_cache` dereference cause refcount WARNs, memory corruption and kernel oops/panic, and the trigger can be repeated freely by an unprivileged process."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:32:22.196Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/051c0bde9f0450a2ec3d62a86d2a0d2fad117f13"
            },
            {
              "url": "https://git.kernel.org/stable/c/db0082825037794c5dba9959c9de13ca34cc5e72"
            },
            {
              "url": "https://git.kernel.org/stable/c/2295a7ef5c8c49241bff769e7826ef2582e532a6"
            },
            {
              "url": "https://git.kernel.org/stable/c/eacb8b195579c174a6d3e12a9690b206eb7f28cf"
            },
            {
              "url": "https://git.kernel.org/stable/c/81dd3c82a456b0015461754be7cb2693991421b4"
            },
            {
              "url": "https://git.kernel.org/stable/c/5af198c387128a9d2ddd620b0f0803564a4d4508"
            },
            {
              "url": "https://git.kernel.org/stable/c/b8af8e6118a6605f0e495a58d591ca94a85a50fc"
            },
            {
              "url": "https://git.kernel.org/stable/c/92f1655aa2b2294d0b49925f3b875a634bd3b59e"
            }
          ],
          "title": "net: fix __dst_negative_advice() race",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-36971",
        "datePublished": "2024-06-10T09:03:23.878Z",
        "dateReserved": "2024-05-30T15:25:07.082Z",
        "dateUpdated": "2026-08-05T11:32:22.196Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-36955 (GCVE-0-2024-36955)

    Vulnerability from cvelistv5 – Published: 2024-05-30 15:35 – Updated: 2026-05-11 20:17
    VLAI
    Title
    ALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node()
    Summary
    In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node() The documentation for device_get_named_child_node() mentions this important point: " The caller is responsible for calling fwnode_handle_put() on the returned fwnode pointer. " Add fwnode_handle_put() to avoid a leaked reference.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-05-31 14:29 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 08c2a4bc9f2acaefbd0158866db5cb3238a68674 , < bd2d9641a39e6b5244230c4b41c4aca83b54b377 (git)
    Affected: 08c2a4bc9f2acaefbd0158866db5cb3238a68674 , < 722d33c442e66e4aabd3e778958d696ff3a2777e (git)
    Affected: 08c2a4bc9f2acaefbd0158866db5cb3238a68674 , < 7db626d2730d3d80fd31638169054b1e507f07bf (git)
    Affected: 08c2a4bc9f2acaefbd0158866db5cb3238a68674 , < 7ef6ecf98ce309b1f4e5a25cddd5965d01feea07 (git)
    Affected: 08c2a4bc9f2acaefbd0158866db5cb3238a68674 , < c158cf914713efc3bcdc25680c7156c48c12ef6a (git)
    Create a notification for this product.
    Linux Linux Affected: 5.12
    Unaffected: 0 , < 5.12 (semver)
    Unaffected: 5.15.159 , ≤ 5.15.* (semver)
    Unaffected: 6.1.91 , ≤ 6.1.* (semver)
    Unaffected: 6.6.31 , ≤ 6.6.* (semver)
    Unaffected: 6.8.10 , ≤ 6.8.* (semver)
    Unaffected: 6.9 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 08c2a4bc9f2a , < bd2d9641a39e (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 08c2a4bc9f2a , < 722d33c442e6 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 08c2a4bc9f2a , < 7db626d2730d (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 08c2a4bc9f2a , < 7ef6ecf98ce3 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 08c2a4bc9f2a , < c158cf914713 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 5.12 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.15.159 , < 5.16 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.1.91 , < 6.2 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.31 , < 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.8.10 , < 6.9 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 5.12
        cpe:2.3:o:linux:linux_kernel:5.12:-:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "bd2d9641a39e",
                    "status": "affected",
                    "version": "08c2a4bc9f2a",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "722d33c442e6",
                    "status": "affected",
                    "version": "08c2a4bc9f2a",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "7db626d2730d",
                    "status": "affected",
                    "version": "08c2a4bc9f2a",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "7ef6ecf98ce3",
                    "status": "affected",
                    "version": "08c2a4bc9f2a",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "c158cf914713",
                    "status": "affected",
                    "version": "08c2a4bc9f2a",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.12",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.16",
                    "status": "unaffected",
                    "version": "5.15.159",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.2",
                    "status": "unaffected",
                    "version": "6.1.91",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.7",
                    "status": "unaffected",
                    "version": "6.6.31",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.9",
                    "status": "unaffected",
                    "version": "6.8.10",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.9"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:5.12:-:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.12"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.7,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-36955",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-31T14:29:10.671529Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-200",
                    "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-06T19:37:57.002Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T03:43:50.678Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/bd2d9641a39e6b5244230c4b41c4aca83b54b377"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/722d33c442e66e4aabd3e778958d696ff3a2777e"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/7db626d2730d3d80fd31638169054b1e507f07bf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/7ef6ecf98ce309b1f4e5a25cddd5965d01feea07"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/c158cf914713efc3bcdc25680c7156c48c12ef6a"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "sound/hda/intel-sdw-acpi.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "bd2d9641a39e6b5244230c4b41c4aca83b54b377",
                  "status": "affected",
                  "version": "08c2a4bc9f2acaefbd0158866db5cb3238a68674",
                  "versionType": "git"
                },
                {
                  "lessThan": "722d33c442e66e4aabd3e778958d696ff3a2777e",
                  "status": "affected",
                  "version": "08c2a4bc9f2acaefbd0158866db5cb3238a68674",
                  "versionType": "git"
                },
                {
                  "lessThan": "7db626d2730d3d80fd31638169054b1e507f07bf",
                  "status": "affected",
                  "version": "08c2a4bc9f2acaefbd0158866db5cb3238a68674",
                  "versionType": "git"
                },
                {
                  "lessThan": "7ef6ecf98ce309b1f4e5a25cddd5965d01feea07",
                  "status": "affected",
                  "version": "08c2a4bc9f2acaefbd0158866db5cb3238a68674",
                  "versionType": "git"
                },
                {
                  "lessThan": "c158cf914713efc3bcdc25680c7156c48c12ef6a",
                  "status": "affected",
                  "version": "08c2a4bc9f2acaefbd0158866db5cb3238a68674",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "sound/hda/intel-sdw-acpi.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.12"
                },
                {
                  "lessThan": "5.12",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.159",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.91",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.31",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.9",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.159",
                      "versionStartIncluding": "5.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.91",
                      "versionStartIncluding": "5.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.31",
                      "versionStartIncluding": "5.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.10",
                      "versionStartIncluding": "5.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9",
                      "versionStartIncluding": "5.12",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node()\n\nThe documentation for device_get_named_child_node() mentions this\nimportant point:\n\n\"\nThe caller is responsible for calling fwnode_handle_put() on the\nreturned fwnode pointer.\n\"\n\nAdd fwnode_handle_put() to avoid a leaked reference."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T20:17:43.940Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/bd2d9641a39e6b5244230c4b41c4aca83b54b377"
            },
            {
              "url": "https://git.kernel.org/stable/c/722d33c442e66e4aabd3e778958d696ff3a2777e"
            },
            {
              "url": "https://git.kernel.org/stable/c/7db626d2730d3d80fd31638169054b1e507f07bf"
            },
            {
              "url": "https://git.kernel.org/stable/c/7ef6ecf98ce309b1f4e5a25cddd5965d01feea07"
            },
            {
              "url": "https://git.kernel.org/stable/c/c158cf914713efc3bcdc25680c7156c48c12ef6a"
            }
          ],
          "title": "ALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node()",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-36955",
        "datePublished": "2024-05-30T15:35:49.256Z",
        "dateReserved": "2024-05-30T15:25:07.080Z",
        "dateUpdated": "2026-05-11T20:17:43.940Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-36932 (GCVE-0-2024-36932)

    Vulnerability from cvelistv5 – Published: 2024-05-30 15:29 – Updated: 2026-05-11 20:17
    VLAI
    Title
    thermal/debugfs: Prevent use-after-free from occurring after cdev removal
    Summary
    In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Prevent use-after-free from occurring after cdev removal Since thermal_debug_cdev_remove() does not run under cdev->lock, it can run in parallel with thermal_debug_cdev_state_update() and it may free the struct thermal_debugfs object used by the latter after it has been checked against NULL. If that happens, thermal_debug_cdev_state_update() will access memory that has been freed already causing the kernel to crash. Address this by using cdev->lock in thermal_debug_cdev_remove() around the cdev->debugfs value check (in case the same cdev is removed at the same time in two different threads) and its reset to NULL. Cc :6.8+ <stable@vger.kernel.org> # 6.8+
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-07 14:04 UTC
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 755113d7678681a137c330f7997ceb680adb644e , < c1279dee33369e2525f532364bb87207d23b9481 (git)
    Affected: 755113d7678681a137c330f7997ceb680adb644e , < d351eb0ab04c3e8109895fc33250cebbce9c11da (git)
    Create a notification for this product.
    Linux Linux Affected: 6.8
    Unaffected: 0 , < 6.8 (semver)
    Unaffected: 6.8.10 , ≤ 6.8.* (semver)
    Unaffected: 6.9 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 755113d76786 , < c1279dee3336 (custom)
    Affected: 755113d76786 , < d351eb0ab04c (custom)
    Affected: 6.8
    Unaffected: 0 , < 6.8 (custom)
    Unaffected: 6.8.10
    Unaffected: 6.9
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "c1279dee3336",
                    "status": "affected",
                    "version": "755113d76786",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "d351eb0ab04c",
                    "status": "affected",
                    "version": "755113d76786",
                    "versionType": "custom"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "lessThan": "6.8",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "status": "unaffected",
                    "version": "6.8.10"
                  },
                  {
                    "status": "unaffected",
                    "version": "6.9"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-36932",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-07T14:04:33.823483Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-07T14:06:48.074Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T03:43:50.540Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/c1279dee33369e2525f532364bb87207d23b9481"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/d351eb0ab04c3e8109895fc33250cebbce9c11da"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/thermal/thermal_debugfs.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "c1279dee33369e2525f532364bb87207d23b9481",
                  "status": "affected",
                  "version": "755113d7678681a137c330f7997ceb680adb644e",
                  "versionType": "git"
                },
                {
                  "lessThan": "d351eb0ab04c3e8109895fc33250cebbce9c11da",
                  "status": "affected",
                  "version": "755113d7678681a137c330f7997ceb680adb644e",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/thermal/thermal_debugfs.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.8"
                },
                {
                  "lessThan": "6.8",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.9",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.10",
                      "versionStartIncluding": "6.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9",
                      "versionStartIncluding": "6.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal/debugfs: Prevent use-after-free from occurring after cdev removal\n\nSince thermal_debug_cdev_remove() does not run under cdev-\u003elock, it can\nrun in parallel with thermal_debug_cdev_state_update() and it may free\nthe struct thermal_debugfs object used by the latter after it has been\nchecked against NULL.\n\nIf that happens, thermal_debug_cdev_state_update() will access memory\nthat has been freed already causing the kernel to crash.\n\nAddress this by using cdev-\u003elock in thermal_debug_cdev_remove() around\nthe cdev-\u003edebugfs value check (in case the same cdev is removed at the\nsame time in two different threads) and its reset to NULL.\n\nCc :6.8+ \u003cstable@vger.kernel.org\u003e # 6.8+"
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T20:17:17.142Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/c1279dee33369e2525f532364bb87207d23b9481"
            },
            {
              "url": "https://git.kernel.org/stable/c/d351eb0ab04c3e8109895fc33250cebbce9c11da"
            }
          ],
          "title": "thermal/debugfs: Prevent use-after-free from occurring after cdev removal",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-36932",
        "datePublished": "2024-05-30T15:29:23.178Z",
        "dateReserved": "2024-05-30T15:25:07.071Z",
        "dateUpdated": "2026-05-11T20:17:17.142Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-36926 (GCVE-0-2024-36926)

    Vulnerability from cvelistv5 – Published: 2024-05-30 15:29 – Updated: 2026-05-23 15:47
    VLAI
    Title
    powerpc/pseries/iommu: LPAR panics during boot up with a frozen PE
    Summary
    In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/iommu: LPAR panics during boot up with a frozen PE At the time of LPAR boot up, partition firmware provides Open Firmware property ibm,dma-window for the PE. This property is provided on the PCI bus the PE is attached to. There are execptions where the partition firmware might not provide this property for the PE at the time of LPAR boot up. One of the scenario is where the firmware has frozen the PE due to some error condition. This PE is frozen for 24 hours or unless the whole system is reinitialized. Within this time frame, if the LPAR is booted, the frozen PE will be presented to the LPAR but ibm,dma-window property could be missing. Today, under these circumstances, the LPAR oopses with NULL pointer dereference, when configuring the PCI bus the PE is attached to. BUG: Kernel NULL pointer dereference on read at 0x000000c8 Faulting instruction address: 0xc0000000001024c0 Oops: Kernel access of bad area, sig: 7 [#1] LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries Modules linked in: Supported: Yes CPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.4.0-150600.9-default #1 Hardware name: IBM,9043-MRX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NM1060_023) hv:phyp pSeries NIP: c0000000001024c0 LR: c0000000001024b0 CTR: c000000000102450 REGS: c0000000037db5c0 TRAP: 0300 Not tainted (6.4.0-150600.9-default) MSR: 8000000002009033 <SF,VEC,EE,ME,IR,DR,RI,LE> CR: 28000822 XER: 00000000 CFAR: c00000000010254c DAR: 00000000000000c8 DSISR: 00080000 IRQMASK: 0 ... NIP [c0000000001024c0] pci_dma_bus_setup_pSeriesLP+0x70/0x2a0 LR [c0000000001024b0] pci_dma_bus_setup_pSeriesLP+0x60/0x2a0 Call Trace: pci_dma_bus_setup_pSeriesLP+0x60/0x2a0 (unreliable) pcibios_setup_bus_self+0x1c0/0x370 __of_scan_bus+0x2f8/0x330 pcibios_scan_phb+0x280/0x3d0 pcibios_init+0x88/0x12c do_one_initcall+0x60/0x320 kernel_init_freeable+0x344/0x3e4 kernel_init+0x34/0x1d0 ret_from_kernel_user_thread+0x14/0x1c
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-07 19:55 UTC
    CWE
    • CWE-476 - NULL Pointer Dereference
    Impacted products
    Vendor Product Version
    Linux Linux Affected: b1fc44eaa9ba31e28c4125d6b9205a3582b47b5d , < 7fb5793c53f8c024e3eae9f0d44eb659aed833c4 (git)
    Affected: b1fc44eaa9ba31e28c4125d6b9205a3582b47b5d , < 802b13b79ab1fef66c6852fc745cf197dca0cb15 (git)
    Affected: b1fc44eaa9ba31e28c4125d6b9205a3582b47b5d , < 2bed905a72485a2b79a001bd7e66c750942d2155 (git)
    Affected: b1fc44eaa9ba31e28c4125d6b9205a3582b47b5d , < 49a940dbdc3107fecd5e6d3063dc07128177e058 (git)
    Affected: b9f08b2649dddd4eb0698cb428b173bb01dd2fc5 (git)
    Affected: 58942f672c6d04b6a3cd7866cb459671df881538 (git)
    Affected: 5.18.18 , < 5.19 (semver)
    Affected: 5.19.2 , < 5.20 (semver)
    Create a notification for this product.
    Linux Linux Affected: 6.0
    Unaffected: 0 , < 6.0 (semver)
    Unaffected: 6.1.91 , ≤ 6.1.* (semver)
    Unaffected: 6.6.31 , ≤ 6.6.* (semver)
    Unaffected: 6.8.10 , ≤ 6.8.* (semver)
    Unaffected: 6.9 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: b1fc44eaa9ba , < 7fb5793c53f8 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: b1fc44eaa9ba , < 802b13b79ab1 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: b1fc44eaa9ba , < 2bed905a7248 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: b1fc44eaa9ba , < 49a940dbdc31 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.1.91 , < 6.2 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.31 , < 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 6.0 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 6.0
        cpe:2.3:o:linux:linux_kernel:6.0:-:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.8.10 , < 6.9 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "7fb5793c53f8",
                    "status": "affected",
                    "version": "b1fc44eaa9ba",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "802b13b79ab1",
                    "status": "affected",
                    "version": "b1fc44eaa9ba",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "2bed905a7248",
                    "status": "affected",
                    "version": "b1fc44eaa9ba",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "49a940dbdc31",
                    "status": "affected",
                    "version": "b1fc44eaa9ba",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.2",
                    "status": "unaffected",
                    "version": "6.1.91",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.7",
                    "status": "unaffected",
                    "version": "6.6.31",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.9"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.0",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:6.0:-:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.9",
                    "status": "unaffected",
                    "version": "6.8.10",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.2,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-36926",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-07T19:55:04.176506Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-476",
                    "description": "CWE-476 NULL Pointer Dereference",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-07T19:55:19.669Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T03:43:50.057Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/7fb5793c53f8c024e3eae9f0d44eb659aed833c4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/802b13b79ab1fef66c6852fc745cf197dca0cb15"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/2bed905a72485a2b79a001bd7e66c750942d2155"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/49a940dbdc3107fecd5e6d3063dc07128177e058"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "arch/powerpc/platforms/pseries/iommu.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "7fb5793c53f8c024e3eae9f0d44eb659aed833c4",
                  "status": "affected",
                  "version": "b1fc44eaa9ba31e28c4125d6b9205a3582b47b5d",
                  "versionType": "git"
                },
                {
                  "lessThan": "802b13b79ab1fef66c6852fc745cf197dca0cb15",
                  "status": "affected",
                  "version": "b1fc44eaa9ba31e28c4125d6b9205a3582b47b5d",
                  "versionType": "git"
                },
                {
                  "lessThan": "2bed905a72485a2b79a001bd7e66c750942d2155",
                  "status": "affected",
                  "version": "b1fc44eaa9ba31e28c4125d6b9205a3582b47b5d",
                  "versionType": "git"
                },
                {
                  "lessThan": "49a940dbdc3107fecd5e6d3063dc07128177e058",
                  "status": "affected",
                  "version": "b1fc44eaa9ba31e28c4125d6b9205a3582b47b5d",
                  "versionType": "git"
                },
                {
                  "status": "affected",
                  "version": "b9f08b2649dddd4eb0698cb428b173bb01dd2fc5",
                  "versionType": "git"
                },
                {
                  "status": "affected",
                  "version": "58942f672c6d04b6a3cd7866cb459671df881538",
                  "versionType": "git"
                },
                {
                  "lessThan": "5.19",
                  "status": "affected",
                  "version": "5.18.18",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.20",
                  "status": "affected",
                  "version": "5.19.2",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "arch/powerpc/platforms/pseries/iommu.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.0"
                },
                {
                  "lessThan": "6.0",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.91",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.31",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.9",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.91",
                      "versionStartIncluding": "6.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.31",
                      "versionStartIncluding": "6.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.10",
                      "versionStartIncluding": "6.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9",
                      "versionStartIncluding": "6.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionStartIncluding": "5.18.18",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionStartIncluding": "5.19.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries/iommu: LPAR panics during boot up with a frozen PE\n\nAt the time of LPAR boot up, partition firmware provides Open Firmware\nproperty ibm,dma-window for the PE. This property is provided on the PCI\nbus the PE is attached to.\n\nThere are execptions where the partition firmware might not provide this\nproperty for the PE at the time of LPAR boot up. One of the scenario is\nwhere the firmware has frozen the PE due to some error condition. This\nPE is frozen for 24 hours or unless the whole system is reinitialized.\n\nWithin this time frame, if the LPAR is booted, the frozen PE will be\npresented to the LPAR but ibm,dma-window property could be missing.\n\nToday, under these circumstances, the LPAR oopses with NULL pointer\ndereference, when configuring the PCI bus the PE is attached to.\n\n  BUG: Kernel NULL pointer dereference on read at 0x000000c8\n  Faulting instruction address: 0xc0000000001024c0\n  Oops: Kernel access of bad area, sig: 7 [#1]\n  LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries\n  Modules linked in:\n  Supported: Yes\n  CPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.4.0-150600.9-default #1\n  Hardware name: IBM,9043-MRX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NM1060_023) hv:phyp pSeries\n  NIP:  c0000000001024c0 LR: c0000000001024b0 CTR: c000000000102450\n  REGS: c0000000037db5c0 TRAP: 0300   Not tainted  (6.4.0-150600.9-default)\n  MSR:  8000000002009033 \u003cSF,VEC,EE,ME,IR,DR,RI,LE\u003e  CR: 28000822  XER: 00000000\n  CFAR: c00000000010254c DAR: 00000000000000c8 DSISR: 00080000 IRQMASK: 0\n  ...\n  NIP [c0000000001024c0] pci_dma_bus_setup_pSeriesLP+0x70/0x2a0\n  LR [c0000000001024b0] pci_dma_bus_setup_pSeriesLP+0x60/0x2a0\n  Call Trace:\n    pci_dma_bus_setup_pSeriesLP+0x60/0x2a0 (unreliable)\n    pcibios_setup_bus_self+0x1c0/0x370\n    __of_scan_bus+0x2f8/0x330\n    pcibios_scan_phb+0x280/0x3d0\n    pcibios_init+0x88/0x12c\n    do_one_initcall+0x60/0x320\n    kernel_init_freeable+0x344/0x3e4\n    kernel_init+0x34/0x1d0\n    ret_from_kernel_user_thread+0x14/0x1c"
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-23T15:47:23.514Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/7fb5793c53f8c024e3eae9f0d44eb659aed833c4"
            },
            {
              "url": "https://git.kernel.org/stable/c/802b13b79ab1fef66c6852fc745cf197dca0cb15"
            },
            {
              "url": "https://git.kernel.org/stable/c/2bed905a72485a2b79a001bd7e66c750942d2155"
            },
            {
              "url": "https://git.kernel.org/stable/c/49a940dbdc3107fecd5e6d3063dc07128177e058"
            }
          ],
          "title": "powerpc/pseries/iommu: LPAR panics during boot up with a frozen PE",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-36926",
        "datePublished": "2024-05-30T15:29:19.691Z",
        "dateReserved": "2024-05-30T15:25:07.069Z",
        "dateUpdated": "2026-05-23T15:47:23.514Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-36913 (GCVE-0-2024-36913)

    Vulnerability from cvelistv5 – Published: 2024-05-30 15:29 – Updated: 2026-08-05 11:32
    VLAI
    Title
    Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails
    Summary
    In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and the resulting memory is shared. Callers need to take care to handle these errors to avoid returning decrypted (shared) memory to the page allocator, which could lead to functional or security issues. VMBus code could free decrypted pages if set_memory_encrypted()/decrypted() fails. Leak the pages if this happens.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-05 14:31 UTC
    CWE
    • CWE-1258 - Exposure of Sensitive System Information Due to Uncleared Debug Information
    Impacted products
    Vendor Product Version
    Linux Linux Affected: f2f136c05fb6093818a3b3fefcba46231ac66a62 , < 7f2afcbfe4f6b6047b5f68db5067b7321e5be125 (git)
    Affected: f2f136c05fb6093818a3b3fefcba46231ac66a62 , < 6123a4e8e25bd40cf44db14694abac00e6b664e6 (git)
    Affected: f2f136c05fb6093818a3b3fefcba46231ac66a62 , < e813a0fc2e597146e9cebea61ced9c796d4e308f (git)
    Affected: f2f136c05fb6093818a3b3fefcba46231ac66a62 , < 03f5a999adba062456c8c818a683beb1b498983a (git)
    Create a notification for this product.
    Linux Linux Affected: 5.16
    Unaffected: 0 , < 5.16 (semver)
    Unaffected: 6.1.143 , ≤ 6.1.* (semver)
    Unaffected: 6.6.31 , ≤ 6.6.* (semver)
    Unaffected: 6.8.10 , ≤ 6.8.* (semver)
    Unaffected: 6.9 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < 6123a4e8e25b (custom)
    Affected: 1da177e4c3f4 , < e813a0fc2e59 (custom)
    Affected: 1da177e4c3f4 , < 03f5a999adba (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6123a4e8e25b",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "e813a0fc2e59",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "03f5a999adba",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.1,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-36913",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-05T14:31:38.077186Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-1258",
                    "description": "CWE-1258 Exposure of Sensitive System Information Due to Uncleared Debug Information",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-05T14:41:56.102Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T17:31:16.014Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/6123a4e8e25bd40cf44db14694abac00e6b664e6"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/e813a0fc2e597146e9cebea61ced9c796d4e308f"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/03f5a999adba062456c8c818a683beb1b498983a"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/hv/connection.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "7f2afcbfe4f6b6047b5f68db5067b7321e5be125",
                  "status": "affected",
                  "version": "f2f136c05fb6093818a3b3fefcba46231ac66a62",
                  "versionType": "git"
                },
                {
                  "lessThan": "6123a4e8e25bd40cf44db14694abac00e6b664e6",
                  "status": "affected",
                  "version": "f2f136c05fb6093818a3b3fefcba46231ac66a62",
                  "versionType": "git"
                },
                {
                  "lessThan": "e813a0fc2e597146e9cebea61ced9c796d4e308f",
                  "status": "affected",
                  "version": "f2f136c05fb6093818a3b3fefcba46231ac66a62",
                  "versionType": "git"
                },
                {
                  "lessThan": "03f5a999adba062456c8c818a683beb1b498983a",
                  "status": "affected",
                  "version": "f2f136c05fb6093818a3b3fefcba46231ac66a62",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/hv/connection.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.16"
                },
                {
                  "lessThan": "5.16",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.143",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.31",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.9",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.143",
                      "versionStartIncluding": "5.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.31",
                      "versionStartIncluding": "5.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.10",
                      "versionStartIncluding": "5.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9",
                      "versionStartIncluding": "5.16",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nDrivers: hv: vmbus: Leak pages if set_memory_encrypted() fails\n\nIn CoCo VMs it is possible for the untrusted host to cause\nset_memory_encrypted() or set_memory_decrypted() to fail such that an\nerror is returned and the resulting memory is shared. Callers need to\ntake care to handle these errors to avoid returning decrypted (shared)\nmemory to the page allocator, which could lead to functional or security\nissues.\n\nVMBus code could free decrypted pages if set_memory_encrypted()/decrypted()\nfails. Leak the pages if this happens."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The attacker is the untrusted Hyper-V host/VMM, which reaches the vulnerable code through the paravirtual page-conversion interface (TDVMCALL\u003cMapGPA\u003e for TDX, GHCB Page State Change for SEV-SNP) of the guest it hosts, not via any network stack. This matches the established scoring for CoCo host-to-guest issues in this subsystem (CVE-2024-57793).\nAC:L - The VMM implements the page-state-change handler invoked by `enc_status_change_prepare`/`_finish` and can deterministically fail it every time, forcing `set_memory_decrypted()`/`set_memory_encrypted()` to return an error on demand. No race, timing, or memory-layout condition outside the attacker\u0027s control is involved.\nPR:N - `vmbus_connect()` runs from `vmbus_bus_init()` during guest boot and `vmbus_disconnect()` from module unload/kexec, so the host needs no account, credential, or capability inside the guest at all. The hypervisor sits entirely outside the guest\u0027s authentication domain in the SEV-SNP/TDX threat model.\nUI:N - The vulnerable path executes automatically when the hv_vmbus driver initializes at guest boot; the host triggers the failed conversion itself and no guest user or administrator has to perform any action.\nS:C - Returning still-shared pages to the buddy allocator breaks the hardware-enforced SEV-SNP/TDX confidential-computing boundary, so data belonging to every other authority in the guest (all processes, containers, and the guest\u0027s protected TCB) becomes host-accessible \u2014 impact far beyond the VMBus driver\u0027s own scope, directly analogous to an IOMMU/DMA boundary bypass.\nC:H - The recycled monitor pages remain mapped shared by the host, so anything the guest later places in them \u2014 slab objects, page cache, anonymous user data, cryptographic keys \u2014 is exposed in plaintext, giving a persistent, continuously refreshed arbitrary-read window into confidential guest memory.\nI:H - The host can write those pages at will while they hold live kernel or user data, yielding an arbitrary-write primitive into whatever object currently occupies them (kernel structures with function pointers or list heads), which is leverageable for control-flow hijack inside the guest.\nA:H - Host modification of live kernel objects in the recycled pages, together with the private/shared state mismatch left by the aborted conversion (#VE / EPT violation on subsequent guest kernel accesses), reliably produces guest memory corruption and kernel panic."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:32:00.757Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/7f2afcbfe4f6b6047b5f68db5067b7321e5be125"
            },
            {
              "url": "https://git.kernel.org/stable/c/6123a4e8e25bd40cf44db14694abac00e6b664e6"
            },
            {
              "url": "https://git.kernel.org/stable/c/e813a0fc2e597146e9cebea61ced9c796d4e308f"
            },
            {
              "url": "https://git.kernel.org/stable/c/03f5a999adba062456c8c818a683beb1b498983a"
            }
          ],
          "title": "Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-36913",
        "datePublished": "2024-05-30T15:29:11.016Z",
        "dateReserved": "2024-05-30T15:25:07.067Z",
        "dateUpdated": "2026-08-05T11:32:00.757Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-36910 (GCVE-0-2024-36910)

    Vulnerability from cvelistv5 – Published: 2024-05-30 15:29 – Updated: 2026-08-05 11:31
    VLAI
    Title
    uio_hv_generic: Don't free decrypted memory
    Summary
    In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Don't free decrypted memory In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and the resulting memory is shared. Callers need to take care to handle these errors to avoid returning decrypted (shared) memory to the page allocator, which could lead to functional or security issues. The VMBus device UIO driver could free decrypted/shared pages if set_memory_decrypted() fails. Check the decrypted field in the gpadl to decide whether to free the memory.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-05-31 15:18 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    Linux Linux Affected: d4dccf353db80e209f262e3973c834e6e48ba9a9 , < dabf12bf994318d939f70d47cfda30e47abb2c54 (git)
    Affected: d4dccf353db80e209f262e3973c834e6e48ba9a9 , < 6466a0f6d235c8a18c602cb587160d7e49876db9 (git)
    Affected: d4dccf353db80e209f262e3973c834e6e48ba9a9 , < fe2c58602354fbd60680dc42ac3a0b772cda7d23 (git)
    Affected: d4dccf353db80e209f262e3973c834e6e48ba9a9 , < 3d788b2fbe6a1a1a9e3db09742b90809d51638b7 (git)
    Create a notification for this product.
    Linux Linux Affected: 5.16
    Unaffected: 0 , < 5.16 (semver)
    Unaffected: 6.1.91 , ≤ 6.1.* (semver)
    Unaffected: 6.6.31 , ≤ 6.6.* (semver)
    Unaffected: 6.8.10 , ≤ 6.8.* (semver)
    Unaffected: 6.9 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < dabf12bf9943 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < 6466a0f6d235 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < fe2c58602354 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < 3d788b2fbe6a (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.1.91 , ≤ 6.1.* (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.31 , ≤ 6.6.* (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.8.10 , ≤ 6.8.* (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "dabf12bf9943",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6466a0f6d235",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "fe2c58602354",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3d788b2fbe6a",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.91",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.31",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThanOrEqual": "6.8.*",
                    "status": "unaffected",
                    "version": "6.8.10",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.9"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.2,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-36910",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-31T15:18:50.996659Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-200",
                    "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:47:42.590Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T03:43:50.063Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/dabf12bf994318d939f70d47cfda30e47abb2c54"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/6466a0f6d235c8a18c602cb587160d7e49876db9"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/fe2c58602354fbd60680dc42ac3a0b772cda7d23"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/3d788b2fbe6a1a1a9e3db09742b90809d51638b7"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/uio/uio_hv_generic.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "dabf12bf994318d939f70d47cfda30e47abb2c54",
                  "status": "affected",
                  "version": "d4dccf353db80e209f262e3973c834e6e48ba9a9",
                  "versionType": "git"
                },
                {
                  "lessThan": "6466a0f6d235c8a18c602cb587160d7e49876db9",
                  "status": "affected",
                  "version": "d4dccf353db80e209f262e3973c834e6e48ba9a9",
                  "versionType": "git"
                },
                {
                  "lessThan": "fe2c58602354fbd60680dc42ac3a0b772cda7d23",
                  "status": "affected",
                  "version": "d4dccf353db80e209f262e3973c834e6e48ba9a9",
                  "versionType": "git"
                },
                {
                  "lessThan": "3d788b2fbe6a1a1a9e3db09742b90809d51638b7",
                  "status": "affected",
                  "version": "d4dccf353db80e209f262e3973c834e6e48ba9a9",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/uio/uio_hv_generic.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.16"
                },
                {
                  "lessThan": "5.16",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.91",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.31",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.9",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.91",
                      "versionStartIncluding": "5.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.31",
                      "versionStartIncluding": "5.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.10",
                      "versionStartIncluding": "5.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9",
                      "versionStartIncluding": "5.16",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nuio_hv_generic: Don\u0027t free decrypted memory\n\nIn CoCo VMs it is possible for the untrusted host to cause\nset_memory_encrypted() or set_memory_decrypted() to fail such that an\nerror is returned and the resulting memory is shared. Callers need to\ntake care to handle these errors to avoid returning decrypted (shared)\nmemory to the page allocator, which could lead to functional or security\nissues.\n\nThe VMBus device UIO driver could free decrypted/shared pages if\nset_memory_decrypted() fails. Check the decrypted field in the gpadl\nto decide whether to free the memory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The attacker is the untrusted hypervisor/host of a confidential VM, which reaches the vulnerable guest code through the paravirtual VMBus interface (GPADL responses, channel rescind, page-visibility hypercall results), not over a network. This is a local, non-network attack channel against the guest kernel.\nAC:L - The host deterministically controls both the GPADL creation status and the outcome of the host-visibility hypercalls backing set_memory_decrypted()/set_memory_encrypted(), and can additionally force the teardown path at will by rescinding the channel, so the failing free of shared memory is reliably reproducible and repeatable.\nPR:N - Privileges are measured against the vulnerable component \u2014 the guest kernel \u2014 and a malicious host holds no credentials or account inside the guest; it needs no guest-side privilege to drive the VMBus failure paths.\nUI:N - No guest user action is needed: the host triggers the probe failure path or forces channel rescind/teardown on its own schedule once the driver is bound at boot.\nS:U - The vulnerable component and the impacted resources are both the guest Linux kernel and its memory; there is no guest-to-host escape or other crossing into a different security authority.\nC:H - Up to 47 MB of still-host-shared pages are returned to the guest page allocator and subsequently reused for arbitrary kernel and user allocations, letting the untrusted host read guest secrets, keys and kernel data \u2014 a total break of the confidential VM\u0027s confidentiality guarantee.\nI:H - The same reallocated pages remain writable by the host, giving an arbitrary write primitive into live guest kernel structures (page tables, credentials, code paths\u0027 data), which is sufficient for full guest kernel compromise.\nA:H - Encryption-state mismatch on the recycled pages leads to corrupted data and faults when the guest accesses them as private memory, and host-controlled writes into arbitrary reallocated kernel memory readily produce a guest kernel panic."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:31:57.546Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/dabf12bf994318d939f70d47cfda30e47abb2c54"
            },
            {
              "url": "https://git.kernel.org/stable/c/6466a0f6d235c8a18c602cb587160d7e49876db9"
            },
            {
              "url": "https://git.kernel.org/stable/c/fe2c58602354fbd60680dc42ac3a0b772cda7d23"
            },
            {
              "url": "https://git.kernel.org/stable/c/3d788b2fbe6a1a1a9e3db09742b90809d51638b7"
            }
          ],
          "title": "uio_hv_generic: Don\u0027t free decrypted memory",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-36910",
        "datePublished": "2024-05-30T15:29:08.902Z",
        "dateReserved": "2024-05-30T15:25:07.067Z",
        "dateUpdated": "2026-08-05T11:31:57.546Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-36905 (GCVE-0-2024-36905)

    Vulnerability from cvelistv5 – Published: 2024-05-30 15:29 – Updated: 2026-05-12 11:54
    VLAI
    Title
    tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets
    Summary
    In the Linux kernel, the following vulnerability has been resolved: tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets TCP_SYN_RECV state is really special, it is only used by cross-syn connections, mostly used by fuzzers. In the following crash [1], syzbot managed to trigger a divide by zero in tcp_rcv_space_adjust() A socket makes the following state transitions, without ever calling tcp_init_transfer(), meaning tcp_init_buffer_space() is also not called. TCP_CLOSE connect() TCP_SYN_SENT TCP_SYN_RECV shutdown() -> tcp_shutdown(sk, SEND_SHUTDOWN) TCP_FIN_WAIT1 To fix this issue, change tcp_shutdown() to not perform a TCP_SYN_RECV -> TCP_FIN_WAIT1 transition, which makes no sense anyway. When tcp_rcv_state_process() later changes socket state from TCP_SYN_RECV to TCP_ESTABLISH, then look at sk->sk_shutdown to finally enter TCP_FIN_WAIT1 state, and send a FIN packet from a sane socket state. This means tcp_send_fin() can now be called from BH context, and must use GFP_ATOMIC allocations. [1] divide error: 0000 [#1] PREEMPT SMP KASAN NOPTI CPU: 1 PID: 5084 Comm: syz-executor358 Not tainted 6.9.0-rc6-syzkaller-00022-g98369dccd2f8 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024 RIP: 0010:tcp_rcv_space_adjust+0x2df/0x890 net/ipv4/tcp_input.c:767 Code: e3 04 4c 01 eb 48 8b 44 24 38 0f b6 04 10 84 c0 49 89 d5 0f 85 a5 03 00 00 41 8b 8e c8 09 00 00 89 e8 29 c8 48 0f af c3 31 d2 <48> f7 f1 48 8d 1c 43 49 8d 96 76 08 00 00 48 89 d0 48 c1 e8 03 48 RSP: 0018:ffffc900031ef3f0 EFLAGS: 00010246 RAX: 0c677a10441f8f42 RBX: 000000004fb95e7e RCX: 0000000000000000 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 RBP: 0000000027d4b11f R08: ffffffff89e535a4 R09: 1ffffffff25e6ab7 R10: dffffc0000000000 R11: ffffffff8135e920 R12: ffff88802a9f8d30 R13: dffffc0000000000 R14: ffff88802a9f8d00 R15: 1ffff1100553f2da FS: 00005555775c0380(0000) GS:ffff8880b9500000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f1155bf2304 CR3: 000000002b9f2000 CR4: 0000000000350ef0 Call Trace: <TASK> tcp_recvmsg_locked+0x106d/0x25a0 net/ipv4/tcp.c:2513 tcp_recvmsg+0x25d/0x920 net/ipv4/tcp.c:2578 inet6_recvmsg+0x16a/0x730 net/ipv6/af_inet6.c:680 sock_recvmsg_nosec net/socket.c:1046 [inline] sock_recvmsg+0x109/0x280 net/socket.c:1068 ____sys_recvmsg+0x1db/0x470 net/socket.c:2803 ___sys_recvmsg net/socket.c:2845 [inline] do_recvmmsg+0x474/0xae0 net/socket.c:2939 __sys_recvmmsg net/socket.c:3018 [inline] __do_sys_recvmmsg net/socket.c:3041 [inline] __se_sys_recvmmsg net/socket.c:3034 [inline] __x64_sys_recvmmsg+0x199/0x250 net/socket.c:3034 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7faeb6363db9 Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 c1 17 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007ffcc1997168 EFLAGS: 00000246 ORIG_RAX: 000000000000012b RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007faeb6363db9 RDX: 0000000000000001 RSI: 0000000020000bc0 RDI: 0000000000000005 RBP: 0000000000000000 R08: 0000000000000000 R09: 000000000000001c R10: 0000000000000122 R11: 0000000000000246 R12: 0000000000000000 R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000001
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-19 18:00 UTC
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < 34e41a031fd7523bf1cd00a2adca2370aebea270 (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < ed5e279b69e007ce6c0fe82a5a534c1b19783214 (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < 413c33b9f3bc36fdf719690a78824db9f88a9485 (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < 2552c9d9440f8e7a2ed0660911ff00f25b90a0a4 (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < 3fe4ef0568a48369b1891395d13ac593b1ba41b1 (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < f47d0d32fa94e815fdd78b8b88684873e67939f4 (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < cbf232ba11bc86a5281b4f00e1151349ef4d45cf (git)
    Affected: 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 , < 94062790aedb505bdda209b10bea47b294d6394f (git)
    Create a notification for this product.
    Linux Linux Affected: 2.6.12
    Unaffected: 0 , < 2.6.12 (semver)
    Unaffected: 4.19.314 , ≤ 4.19.* (semver)
    Unaffected: 5.4.276 , ≤ 5.4.* (semver)
    Unaffected: 5.10.217 , ≤ 5.10.* (semver)
    Unaffected: 5.15.159 , ≤ 5.15.* (semver)
    Unaffected: 6.1.91 , ≤ 6.1.* (semver)
    Unaffected: 6.6.31 , ≤ 6.6.* (semver)
    Unaffected: 6.8.10 , ≤ 6.8.* (semver)
    Unaffected: 6.9 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < 34e41a031fd7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < ed5e279b69e0 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < 413c33b9f3bc (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f , < 2552c9d9440f (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < 3fe4ef0568a4 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < f47d0d32fa94 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < cbf232ba11bc (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 1da177e4c3f4 , < 94062790aedb (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 4.19.314 , < 4.20 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.10.217 , < 5.11 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.15.159 , < 5.16 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.1.91 , < 6.2 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.6.31 , < 6.7 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.9
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 0 , < 2.6.12 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 2.6.12
        cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 5.4.276 , < 5.5 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Unaffected: 6.8.10 , < 6.9 (custom)
        cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Siemens RUGGEDCOM RST2428P Affected: 0 , < V3.1 (custom)
    Create a notification for this product.
    Siemens SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family Unaffected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SCALANCE XCM-/XRM-/XCH-/XRH-300 family Affected: 0 , < V3.1 (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.0 , < V3.1.5 (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP Affected: V3.1.0 , < V3.1.5 (custom)
    Create a notification for this product.
    Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.0 , < V3.1.5 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "34e41a031fd7",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "ed5e279b69e0",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "413c33b9f3bc",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "2552c9d9440f",
                    "status": "affected",
                    "version": "1da177e4c3f",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3fe4ef0568a4",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "f47d0d32fa94",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "cbf232ba11bc",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "94062790aedb",
                    "status": "affected",
                    "version": "1da177e4c3f4",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "4.20",
                    "status": "unaffected",
                    "version": "4.19.314",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.11",
                    "status": "unaffected",
                    "version": "5.10.217",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.16",
                    "status": "unaffected",
                    "version": "5.15.159",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.2",
                    "status": "unaffected",
                    "version": "6.1.91",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.7",
                    "status": "unaffected",
                    "version": "6.6.31",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "6.9"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "2.6.12",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.6.12"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "5.5",
                    "status": "unaffected",
                    "version": "5.4.276",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "6.9",
                    "status": "unaffected",
                    "version": "6.8.10",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-36905",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-19T18:00:22.813648Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-14T16:43:30.740Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "url": "https://github.com/cisagov/vulnrichment/issues/130"
              },
              {
                "url": "https://www.openwall.com/lists/oss-security/2024/11/12/4"
              },
              {
                "url": "https://alas.aws.amazon.com/cve/html/CVE-2024-36905.html"
              },
              {
                "url": "https://access.redhat.com/security/cve/cve-2024-36905"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-11-12T19:02:41.493Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/34e41a031fd7523bf1cd00a2adca2370aebea270"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/ed5e279b69e007ce6c0fe82a5a534c1b19783214"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/413c33b9f3bc36fdf719690a78824db9f88a9485"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/2552c9d9440f8e7a2ed0660911ff00f25b90a0a4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/3fe4ef0568a48369b1891395d13ac593b1ba41b1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/f47d0d32fa94e815fdd78b8b88684873e67939f4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/cbf232ba11bc86a5281b4f00e1151349ef4d45cf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/94062790aedb505bdda209b10bea47b294d6394f"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html"
              },
              {
                "url": "https://security.netapp.com/advisory/ntap-20240905-0005/"
              },
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/10/29/1"
              },
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/10/30/1"
              },
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/11/12/4"
              },
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/11/12/5"
              },
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/11/12/6"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "RUGGEDCOM RST2428P",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SCALANCE XCM-/XRM-/XCH-/XRH-300 family",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T11:54:14.051Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-398330.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-613116.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/ipv4/tcp.c",
                "net/ipv4/tcp_input.c",
                "net/ipv4/tcp_output.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "34e41a031fd7523bf1cd00a2adca2370aebea270",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "ed5e279b69e007ce6c0fe82a5a534c1b19783214",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "413c33b9f3bc36fdf719690a78824db9f88a9485",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "2552c9d9440f8e7a2ed0660911ff00f25b90a0a4",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "3fe4ef0568a48369b1891395d13ac593b1ba41b1",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "f47d0d32fa94e815fdd78b8b88684873e67939f4",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "cbf232ba11bc86a5281b4f00e1151349ef4d45cf",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                },
                {
                  "lessThan": "94062790aedb505bdda209b10bea47b294d6394f",
                  "status": "affected",
                  "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/ipv4/tcp.c",
                "net/ipv4/tcp_input.c",
                "net/ipv4/tcp_output.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.6.12"
                },
                {
                  "lessThan": "2.6.12",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "4.19.*",
                  "status": "unaffected",
                  "version": "4.19.314",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.276",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.217",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.159",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.91",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.31",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.9",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.19.314",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.276",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.217",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.159",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.91",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.31",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.10",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets\n\nTCP_SYN_RECV state is really special, it is only used by\ncross-syn connections, mostly used by fuzzers.\n\nIn the following crash [1], syzbot managed to trigger a divide\nby zero in tcp_rcv_space_adjust()\n\nA socket makes the following state transitions,\nwithout ever calling tcp_init_transfer(),\nmeaning tcp_init_buffer_space() is also not called.\n\n         TCP_CLOSE\nconnect()\n         TCP_SYN_SENT\n         TCP_SYN_RECV\nshutdown() -\u003e tcp_shutdown(sk, SEND_SHUTDOWN)\n         TCP_FIN_WAIT1\n\nTo fix this issue, change tcp_shutdown() to not\nperform a TCP_SYN_RECV -\u003e TCP_FIN_WAIT1 transition,\nwhich makes no sense anyway.\n\nWhen tcp_rcv_state_process() later changes socket state\nfrom TCP_SYN_RECV to TCP_ESTABLISH, then look at\nsk-\u003esk_shutdown to finally enter TCP_FIN_WAIT1 state,\nand send a FIN packet from a sane socket state.\n\nThis means tcp_send_fin() can now be called from BH\ncontext, and must use GFP_ATOMIC allocations.\n\n[1]\ndivide error: 0000 [#1] PREEMPT SMP KASAN NOPTI\nCPU: 1 PID: 5084 Comm: syz-executor358 Not tainted 6.9.0-rc6-syzkaller-00022-g98369dccd2f8 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\n RIP: 0010:tcp_rcv_space_adjust+0x2df/0x890 net/ipv4/tcp_input.c:767\nCode: e3 04 4c 01 eb 48 8b 44 24 38 0f b6 04 10 84 c0 49 89 d5 0f 85 a5 03 00 00 41 8b 8e c8 09 00 00 89 e8 29 c8 48 0f af c3 31 d2 \u003c48\u003e f7 f1 48 8d 1c 43 49 8d 96 76 08 00 00 48 89 d0 48 c1 e8 03 48\nRSP: 0018:ffffc900031ef3f0 EFLAGS: 00010246\nRAX: 0c677a10441f8f42 RBX: 000000004fb95e7e RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: 0000000027d4b11f R08: ffffffff89e535a4 R09: 1ffffffff25e6ab7\nR10: dffffc0000000000 R11: ffffffff8135e920 R12: ffff88802a9f8d30\nR13: dffffc0000000000 R14: ffff88802a9f8d00 R15: 1ffff1100553f2da\nFS:  00005555775c0380(0000) GS:ffff8880b9500000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f1155bf2304 CR3: 000000002b9f2000 CR4: 0000000000350ef0\nCall Trace:\n \u003cTASK\u003e\n  tcp_recvmsg_locked+0x106d/0x25a0 net/ipv4/tcp.c:2513\n  tcp_recvmsg+0x25d/0x920 net/ipv4/tcp.c:2578\n  inet6_recvmsg+0x16a/0x730 net/ipv6/af_inet6.c:680\n  sock_recvmsg_nosec net/socket.c:1046 [inline]\n  sock_recvmsg+0x109/0x280 net/socket.c:1068\n  ____sys_recvmsg+0x1db/0x470 net/socket.c:2803\n  ___sys_recvmsg net/socket.c:2845 [inline]\n  do_recvmmsg+0x474/0xae0 net/socket.c:2939\n  __sys_recvmmsg net/socket.c:3018 [inline]\n  __do_sys_recvmmsg net/socket.c:3041 [inline]\n  __se_sys_recvmmsg net/socket.c:3034 [inline]\n  __x64_sys_recvmmsg+0x199/0x250 net/socket.c:3034\n  do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n  do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7faeb6363db9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 c1 17 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007ffcc1997168 EFLAGS: 00000246 ORIG_RAX: 000000000000012b\nRAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007faeb6363db9\nRDX: 0000000000000001 RSI: 0000000020000bc0 RDI: 0000000000000005\nRBP: 0000000000000000 R08: 0000000000000000 R09: 000000000000001c\nR10: 0000000000000122 R11: 0000000000000246 R12: 0000000000000000\nR13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000001"
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T20:16:45.826Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/34e41a031fd7523bf1cd00a2adca2370aebea270"
            },
            {
              "url": "https://git.kernel.org/stable/c/ed5e279b69e007ce6c0fe82a5a534c1b19783214"
            },
            {
              "url": "https://git.kernel.org/stable/c/413c33b9f3bc36fdf719690a78824db9f88a9485"
            },
            {
              "url": "https://git.kernel.org/stable/c/2552c9d9440f8e7a2ed0660911ff00f25b90a0a4"
            },
            {
              "url": "https://git.kernel.org/stable/c/3fe4ef0568a48369b1891395d13ac593b1ba41b1"
            },
            {
              "url": "https://git.kernel.org/stable/c/f47d0d32fa94e815fdd78b8b88684873e67939f4"
            },
            {
              "url": "https://git.kernel.org/stable/c/cbf232ba11bc86a5281b4f00e1151349ef4d45cf"
            },
            {
              "url": "https://git.kernel.org/stable/c/94062790aedb505bdda209b10bea47b294d6394f"
            },
            {
              "url": "https://www.openwall.com/lists/oss-security/2024/10/29/1"
            }
          ],
          "title": "tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-36905",
        "datePublished": "2024-05-30T15:29:06.046Z",
        "dateReserved": "2024-05-30T15:25:07.067Z",
        "dateUpdated": "2026-05-12T11:54:14.051Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }