CVE-2024-49855

HIGH EPSS 10.1%
Published Oct 21, 20241y ago · Modified Jun 17, 20261w ago
7.0 CVSS 3.1
High
Find Similar
Published Oct 21, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: nbd: fix race between timeout and normal completion If request timetout is handled by nbd_requeue_cmd(), normal completion has to be stopped for avoiding to complete this requeued request, other use-after-free can be triggered. Fix the race by clearing NBD_CMD_INFLIGHT in nbd_requeue_cmd(), meantime make sure that cmd->lock is grabbed for clearing the flag and the requeue.

CVSS Details

Base Score
7.0
Exploitability
1.0
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
10.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-416 Use After Free Memory Safety

Affected Products 6

VendorProductVersionRange
linuxlinux_kernel*≥5.18.4  –  <5.19
linuxlinux_kernel*≥5.19  –  <6.1.113
linuxlinux_kernel*≥6.2  –  <6.6.54
linuxlinux_kernel*≥6.7  –  <6.10.13
linuxlinux_kernel*≥6.11  –  <6.11.2
linuxlinux_kernel5.17.15any

References 6

  • git.kernel.org https://git.kernel.org/stable/c/5236ada8ebbd9e7461f17477357582f5be4f46f7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6e73b946a379a1dfbb62626af93843bdfb53753d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9a74c3e6c0d686c26ba2aab66d15ddb89dc139cc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9c25faf72d780a9c71081710cd48759d61ff6e9b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c9ea57c91f03bcad415e1a20113bdb2077bcf990
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/5236ada8ebbd9e7461f17477357582f5be4f46f7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6e73b946a379a1dfbb62626af93843bdfb53753d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9a74c3e6c0d686c26ba2aab66d15ddb89dc139cc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9c25faf72d780a9c71081710cd48759d61ff6e9b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c9ea57c91f03bcad415e1a20113bdb2077bcf990
    Patch