CVE-2024-26923Race Condition in Linux

CWE-362Race Condition56 documents8 sources
Severity
4.7MEDIUMNVD
OSV7.0OSV6.8OSV5.5
EPSS
0.0%
top 98.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 25
Latest updateNov 5

Description

In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix garbage collector racing against connect() Garbage collector does not take into account the risk of embryo getting enqueued during the garbage collection. If such embryo has a peer that carries SCM_RIGHTS, two consecutive passes of scan_children() may see a different set of children. Leading to an incorrectly elevated inflight count, and then a dangling pointer within the gc_inflight_list. sockets are AF_UNIX/SOC

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages6 packages

NVDlinux/linux_kernel2.6.234.19.314+7
Debianlinux/linux_kernel< 5.10.216-1+3
Ubuntulinux/linux_kernel< 5.4.0-189.209+8
CVEListV5linux/linux1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9a36ae0ec2353015f0f6762e59f4c2dbc0c906423+8
debiandebian/linux< linux 6.1.90-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

27
OSV
Kernel Live Patch Security Notice2024-11-05
OSV
linux-xilinx-zynqmp vulnerabilities2024-09-18
OSV
linux-oem-6.5 vulnerabilities2024-08-02
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2024-07-31
OSV
linux-gcp-5.15 vulnerabilities2024-07-30

📋Vendor Advisories

27
Ubuntu
Kernel Live Patch Security Notice2024-11-05
Ubuntu
Linux kernel vulnerabilities2024-09-18
Ubuntu
Linux kernel vulnerabilities2024-08-02
Ubuntu
Linux kernel vulnerabilities2024-07-31
Ubuntu
Linux kernel vulnerabilities2024-07-30

💬Community

1
Bugzilla
CVE-2024-26923 kernel: af_unix: Fix garbage collector racing against connect()2024-04-25