CVE-2024-53164

MEDIUM EPSS 16.1%
Published Dec 27, 20241y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Dec 27, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: net: sched: fix ordering of qlen adjustment Changes to sch->q.qlen around qdisc_tree_reduce_backlog() need to happen _before_ a call to said function because otherwise it may fail to notify parent qdiscs when the child is about to become empty.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
16.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 7

VendorProductVersionRange
linuxlinux_kernel* <5.4.289
linuxlinux_kernel*≥5.5  –  <5.10.233
linuxlinux_kernel*≥5.11  –  <5.15.176
linuxlinux_kernel*≥5.16  –  <6.1.122
linuxlinux_kernel*≥6.2  –  <6.6.68
linuxlinux_kernel*≥6.7  –  <6.12.7
linuxlinux_kernel6.13any

References 9

  • git.kernel.org https://git.kernel.org/stable/c/33db36b3c53d0fda2699ea39ba72bee4de8336e8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/44782565e1e6174c94bddfa72ac7267cd09c1648
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/489422e2befff88a1de52b2acebe7b333bded025
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5e473f462a16f1a34e49ea4289a667d2e4f35b52
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5eb7de8cd58e73851cd37ff8d0666517d9926948
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/97e13434b5da8e91bdf965352fad2141d13d72d3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e3e54ad9eff8bdaa70f897e5342e34b76109497f
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/33db36b3c53d0fda2699ea39ba72bee4de8336e8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/44782565e1e6174c94bddfa72ac7267cd09c1648
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/489422e2befff88a1de52b2acebe7b333bded025
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5e473f462a16f1a34e49ea4289a667d2e4f35b52
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5eb7de8cd58e73851cd37ff8d0666517d9926948
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/97e13434b5da8e91bdf965352fad2141d13d72d3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e3e54ad9eff8bdaa70f897e5342e34b76109497f
    Patch