CVE-2024-26923 — Race Condition in Linux
Severity
4.7MEDIUMNVD
OSV7.0OSV6.8OSV5.5
EPSS
0.0%
top 98.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 25
Latest updateNov 5
Description
In the Linux kernel, the following vulnerability has been resolved:
af_unix: Fix garbage collector racing against connect()
Garbage collector does not take into account the risk of embryo getting
enqueued during the garbage collection. If such embryo has a peer that
carries SCM_RIGHTS, two consecutive passes of scan_children() may see a
different set of children. Leading to an incorrectly elevated inflight
count, and then a dangling pointer within the gc_inflight_list.
sockets are AF_UNIX/SOC…
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6
Affected Packages6 packages
▶CVEListV5linux/linux1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 — a36ae0ec2353015f0f6762e59f4c2dbc0c906423+8
Also affects: Debian Linux 10.0