cbcvebase.
CVE-2024-39494
published 2024-07-12

CVE-2024-39494: In the Linux kernel, the following vulnerability has been resolved: ima: Fix use-after-free on a dentry's dname.name ->d_name.name can change on rename and the…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.31%
23.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ima: Fix use-after-free on a dentry's dname.name ->d_name.name can change on rename and the earlier value can be freed; there are conditions sufficient to stabilize it (->d_lock on dentry, ->d_lock on its parent, ->i_rwsem exclusive on the parent's inode, rename_lock), but none of those are met at any of the sites. Take a stable snapshot of the name instead.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 2fe5d6def1672ae6635dd71867bf36dcfaa7434b < 480afcbeb7aaaa22677d3dd48ec590b441eaac1a480afcbeb7aaaa22677d3dd48ec590b441eaac1a
linuxlinux>= 2fe5d6def1672ae6635dd71867bf36dcfaa7434b < edf287bc610b18d7a9c0c0c1cb2e97b9348c71bbedf287bc610b18d7a9c0c0c1cb2e97b9348c71bb
linuxlinux>= 2fe5d6def1672ae6635dd71867bf36dcfaa7434b < 0b31e28fbd773aefb6164687e0767319b81998290b31e28fbd773aefb6164687e0767319b8199829
linuxlinux>= 2fe5d6def1672ae6635dd71867bf36dcfaa7434b < 7fb374981e31c193b1152ed8d3b0a95b671330d47fb374981e31c193b1152ed8d3b0a95b671330d4
linuxlinux>= 2fe5d6def1672ae6635dd71867bf36dcfaa7434b < dd431c3ac1fc34a9268580dd59ad3e3c76b32a8cdd431c3ac1fc34a9268580dd59ad3e3c76b32a8c
linuxlinux>= 2fe5d6def1672ae6635dd71867bf36dcfaa7434b < a78a6f0da57d058e2009e9958fdcef66f165208ca78a6f0da57d058e2009e9958fdcef66f165208c
linuxlinux>= 2fe5d6def1672ae6635dd71867bf36dcfaa7434b < be84f32bb2c981ca670922e047cdde1488b233debe84f32bb2c981ca670922e047cdde1488b233de
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-196.2165.4.0-196.216
linuxlinux_kernel>= 0 < 5.15.0-122.1325.15.0-122.132
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 0 < 4.4.0-260.2944.4.0-260.294
linuxlinux_kernel>= 0 < 4.15.0-230.2424.15.0-230.242
linuxlinux_kernel>= 3.19 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.976.1.97
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.2 < 6.6.356.6.35

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.