CVE-2024-43883

HIGH EPSS 12.8%
Published Aug 23, 20241y ago · Modified Jun 17, 20262w ago
7.0 CVSS 3.1
High
Find Similar
Published Aug 23, 2024 1y ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places the driver carries stale pointers to references that can still be used. Make sure that does not happen. This strictly speaking closes ZDI-CAN-22273, though there may be similar races in the driver.

CVSS Details

Base Score
7.0
Exploitability
1.0
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
12.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-416 Use After Free Memory Safety

Affected Products 9

VendorProductVersionRange
linuxlinux_kernel* <4.19.320
linuxlinux_kernel*≥4.20  –  <5.4.282
linuxlinux_kernel*≥5.5  –  <5.10.224
linuxlinux_kernel*≥5.11  –  <5.15.165
linuxlinux_kernel*≥5.16  –  <6.1.105
linuxlinux_kernel*≥6.2  –  <6.6.46
linuxlinux_kernel*≥6.7  –  <6.10.5
linuxlinux_kernel6.11any
linuxlinux_kernel6.11any

References 10

  • git.kernel.org https://git.kernel.org/stable/c/128e82e41cf7d74a562726c1587d9d2ede1a0a37
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4dacdb9720aaab10b6be121eae55820174d97174
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/585e6bc7d0a9bf73a8be3d3fb34e86b90cc61a14
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5a3c473b28ae1c1f7c4dc129e30cb19ae6e96f89
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9c3746ce8d8fcb3a2405644fc0eec7fc5312de80
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/afdcfd3d6fcdeca2735ca8d994c5f2d24a368f0a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c3d0857b7fc2c49f68f89128a5440176089a8f54
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e8c1e606dab8c56cf074b43b98d0805de7322ba2
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/128e82e41cf7d74a562726c1587d9d2ede1a0a37
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4dacdb9720aaab10b6be121eae55820174d97174
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/585e6bc7d0a9bf73a8be3d3fb34e86b90cc61a14
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5a3c473b28ae1c1f7c4dc129e30cb19ae6e96f89
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9c3746ce8d8fcb3a2405644fc0eec7fc5312de80
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/afdcfd3d6fcdeca2735ca8d994c5f2d24a368f0a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c3d0857b7fc2c49f68f89128a5440176089a8f54
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e8c1e606dab8c56cf074b43b98d0805de7322ba2
    Patch