cbcvebase.
CVE-2024-38545
published 2024-06-19

CVE-2024-38545: In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix UAF for cq async event The refcount of CQ is not protected by locks. When CQ…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.7th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix UAF for cq async event The refcount of CQ is not protected by locks. When CQ asynchronous events and CQ destruction are concurrent, CQ may have been released, which will cause UAF. Use the xa_lock() to protect the CQ refcount.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 9a4435375cd151e07c0c38fa601b00115986091b < 330c825e66ef65278e4ebe57fd49c1d6f3f4e34e330c825e66ef65278e4ebe57fd49c1d6f3f4e34e
linuxlinux>= 9a4435375cd151e07c0c38fa601b00115986091b < 763780ef0336a973e933e40e919339381732dcaf763780ef0336a973e933e40e919339381732dcaf
linuxlinux>= 9a4435375cd151e07c0c38fa601b00115986091b < 63da190eeb5c9d849b71f457b15b308c94cbaf0863da190eeb5c9d849b71f457b15b308c94cbaf08
linuxlinux>= 9a4435375cd151e07c0c38fa601b00115986091b < 39d26cf46306bdc7ae809ecfdbfeff5aa109891139d26cf46306bdc7ae809ecfdbfeff5aa1098911
linuxlinux>= 9a4435375cd151e07c0c38fa601b00115986091b < 37a7559dc1358a8d300437e99ed8ecdab067150737a7559dc1358a8d300437e99ed8ecdab0671507
linuxlinux>= 9a4435375cd151e07c0c38fa601b00115986091b < a942ec2745ca864cd8512142100e4027dc306a42a942ec2745ca864cd8512142100e4027dc306a42
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 4.9 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.936.1.93
linuxlinux_kernel>= 6.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.8.126.8.12
linuxlinux_kernel>= 6.9 < 6.9.36.9.3
msrccbl2_kernel_5.15.176.3-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_oracle9.8CRITICAL
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.