cbcvebase.
CVE-2024-39493
published 2024-07-10

CVE-2024-39493: In the Linux kernel, the following vulnerability has been resolved: crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak Using completion_done to determine whether…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak Using completion_done to determine whether the caller has gone away only works after a complete call. Furthermore it's still possible that the caller has not yet called wait_for_completion, resulting in another potential UAF. Fix this by making the caller use cancel_work_sync and then freeing the memory safely.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 226fc408c5fcd23cc4186f05ea3a09a7a9aef2f7 < e7428e7e3fe94a5089dc12ffe5bc31574d2315ade7428e7e3fe94a5089dc12ffe5bc31574d2315ad
linuxlinux>= 4.19.312 < 4.19.3164.19.316
linuxlinux>= 4ae5a97781ce7d6ecc9c7055396535815b64ca4f < 3fb4601e0db10d4fe25e46f3fa308d40d37366bd3fb4601e0db10d4fe25e46f3fa308d40d37366bd
linuxlinux>= 5.10.215 < 5.10.2195.10.219
linuxlinux>= 5.15.154 < 5.15.1615.15.161
linuxlinux>= 5.4.274 < 5.4.2785.4.278
linuxlinux>= 6.1.84 < 6.1.946.1.94
linuxlinux>= 6.6.24 < 6.6.346.6.34
linuxlinux>= 6.7.12 < 6.86.8
linuxlinux>= 6.8.3 < 6.96.9
linuxlinux>= 7d42e097607c4d246d99225bf2b195b6167a210c < d0fd124972724cce0d48b9865ce3e273ef69e246d0fd124972724cce0d48b9865ce3e273ef69e246
linuxlinux>= 7d42e097607c4d246d99225bf2b195b6167a210c < d3b17c6d9dddc2db3670bc9be628b122416a3d26d3b17c6d9dddc2db3670bc9be628b122416a3d26
linuxlinux>= 8a5a7611ccc7b1fba8d933a9f22a2e76859d94dc < c2d443aa1ae3175c13a665f3a24b8acd759ce9c3c2d443aa1ae3175c13a665f3a24b8acd759ce9c3
linuxlinux>= 8e81cd58aee14a470891733181a47d123193ba81 < 6396b33e98c096bff9c253ed49c008247963492a6396b33e98c096bff9c253ed49c008247963492a
linuxlinux>= d03092550f526a79cf1ade7f0dfa74906f39eb71 < a718b6d2a329e069b27d9049a71be5931e71d960a718b6d2a329e069b27d9049a71be5931e71d960
linuxlinux>= daba62d9eeddcc5b1081be7d348ca836c83c59d7 < 0ce5964b82f212f4df6a9813f09a0b5de15bd9c80ce5964b82f212f4df6a9813f09a0b5de15bd9c8
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.