cbcvebase.
CVE-2024-39292
published 2024-06-24

CVE-2024-39292: In the Linux kernel, the following vulnerability has been resolved: um: Add winch to winch_handlers before registering winch IRQ Registering a winch IRQ is…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.2th percentile
In the Linux kernel, the following vulnerability has been resolved: um: Add winch to winch_handlers before registering winch IRQ Registering a winch IRQ is racy, an interrupt may occur before the winch is added to the winch_handlers list. If that happens, register_winch_irq() adds to that list a winch that is scheduled to be (or has already been) freed, causing a panic later in winch_cleanup(). Avoid the race by adding the winch to the winch_handlers list before registering the IRQ, and rolling back if um_request_irq() fails.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 42a359e31a0e438b5b978a8f0fecdbd3c86bb033 < 66ea9a7c6824821476914bed21a476cd20094f3366ea9a7c6824821476914bed21a476cd20094f33
linuxlinux>= 42a359e31a0e438b5b978a8f0fecdbd3c86bb033 < dc1ff95602ee908fcd7d8acee7a0dadb61b1a0c0dc1ff95602ee908fcd7d8acee7a0dadb61b1a0c0
linuxlinux>= 42a359e31a0e438b5b978a8f0fecdbd3c86bb033 < 351d1a64544944b44732f6a64ed65573b00b9e14351d1a64544944b44732f6a64ed65573b00b9e14
linuxlinux>= 42a359e31a0e438b5b978a8f0fecdbd3c86bb033 < 31960d991e43c8d6dc07245f19fc13398e90ead231960d991e43c8d6dc07245f19fc13398e90ead2
linuxlinux>= 42a359e31a0e438b5b978a8f0fecdbd3c86bb033 < 0c02d425a2fbe52643a5859a779db0329e7dddd40c02d425a2fbe52643a5859a779db0329e7dddd4
linuxlinux>= 42a359e31a0e438b5b978a8f0fecdbd3c86bb033 < 434a06c38ee1217a8baa0dd7c37cc85d50138fb0434a06c38ee1217a8baa0dd7c37cc85d50138fb0
linuxlinux>= 42a359e31a0e438b5b978a8f0fecdbd3c86bb033 < 73b8e21f76c7dda4905655d2e2c17dc5a73b87f173b8e21f76c7dda4905655d2e2c17dc5a73b87f1
linuxlinux>= 42a359e31a0e438b5b978a8f0fecdbd3c86bb033 < a0fbbd36c156b9f7b2276871d499c9943dfe5101a0fbbd36c156b9f7b2276871d499c9943dfe5101
linuxlinux_kernel< 2.6.232.6.23
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-119.1295.15.0-119.129
linuxlinux_kernel>= 0 < 6.8.0-41.416.8.0-41.41
linuxlinux_kernel>= 0 < 4.4.0-258.2924.4.0-258.292
linuxlinux_kernel>= 0 < 4.15.0-228.2404.15.0-228.240
linuxlinux_kernel>= 4.19 < 4.19.3164.19.316
linuxlinux_kernel>= 5.10 < 5.10.2195.10.219
linuxlinux_kernel>= 5.15 < 5.15.1615.15.161
linuxlinux_kernel>= 5.4 < 5.4.2785.4.278

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.4HIGH
vendor_ubuntu8.4HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.