CVE-2024-49864

MEDIUM EPSS 6.9%
Published Oct 21, 20241y ago · Modified Jun 17, 20261w ago
4.7 CVSS 3.1
Medium
Find Similar
Published Oct 21, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix a race between socket set up and I/O thread creation In rxrpc_open_socket(), it sets up the socket and then sets up the I/O thread that will handle it. This is a problem, however, as there's a gap between the two phases in which a packet may come into rxrpc_encap_rcv() from the UDP packet but we oops when trying to wake the not-yet created I/O thread. As a quick fix, just make rxrpc_encap_rcv() discard the packet if there's no I/O thread yet. A better, but more intrusive fix would perhaps be to rearrange things such that the socket creation is done by the I/O thread.

CVSS Details

Base Score
4.7
Exploitability
1.0
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
6.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-362

Affected Products 5

VendorProductVersionRange
linuxlinux_kernel*≥6.2  –  ≤6.6.55
linuxlinux_kernel*≥6.10  –  <6.10.14
linuxlinux_kernel*≥6.11  –  <6.11.3
linuxlinux_kernel6.12any
linuxlinux_kernel6.12any

References 4

  • git.kernel.org https://git.kernel.org/stable/c/56e415202b8a17de6496f4023e545fcb66f118ec
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bc212465326e8587325f520a052346f0b57360e6
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c64f5fc95e9612fdf75587c8e21e494e614c18e2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cdf4bbbdb956d7426f687f38757ebca2a2759a0f
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/56e415202b8a17de6496f4023e545fcb66f118ec
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bc212465326e8587325f520a052346f0b57360e6
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c64f5fc95e9612fdf75587c8e21e494e614c18e2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cdf4bbbdb956d7426f687f38757ebca2a2759a0f
    Patch