cbcvebase.
CVE-2024-27067
published 2024-05-01

CVE-2024-27067: In the Linux kernel, the following vulnerability has been resolved: xen/evtchn: avoid WARN() when unbinding an event channel When unbinding a user event…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.8th percentile
In the Linux kernel, the following vulnerability has been resolved: xen/evtchn: avoid WARN() when unbinding an event channel When unbinding a user event channel, the related handler might be called a last time in case the kernel was built with CONFIG_DEBUG_SHIRQ. This might cause a WARN() in the handler. Avoid that by adding an "unbinding" flag to struct user_event which will short circuit the handler.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.12-1 (forky)linux 6.7.12-1 (forky)
linuxlinux
linuxlinux>= 3c8f5965a99397368d3762a9814a21a3e442e1a4 < 99e425032c6ec13584d3cd33846e0c7307501b4799e425032c6ec13584d3cd33846e0c7307501b47
linuxlinux>= 6.6.19 < 6.6.236.6.23
linuxlinux>= 9e90e58c11b74c2bddac4b2702cf79d36b981278 < 35485dad6e28f9b17884764d4692b1655cb848d035485dad6e28f9b17884764d4692b1655cb848d0
linuxlinux>= 9e90e58c11b74c2bddac4b2702cf79d36b981278 < 9e2d4b58c1da48a32905802aaeadba7084b468959e2d4b58c1da48a32905802aaeadba7084b46895
linuxlinux>= 9e90e58c11b74c2bddac4b2702cf79d36b981278 < 51c23bd691c0f1fb95b29731c356c6fd69925d1751c23bd691c0f1fb95b29731c356c6fd69925d17
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 6.6.19 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.35.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.