cbcvebase.
CVE-2024-39495
published 2024-07-12

CVE-2024-39495: In the Linux kernel, the following vulnerability has been resolved: greybus: Fix use-after-free bug in gb_interface_release due to race condition. In…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.33%
25.0th percentile
In the Linux kernel, the following vulnerability has been resolved: greybus: Fix use-after-free bug in gb_interface_release due to race condition. In gb_interface_create, &intf->mode_switch_completion is bound with gb_interface_mode_switch_work. Then it will be started by gb_interface_request_mode_switch. Here is the relevant code. if (!queue_work(system_long_wq, &intf->mode_switch_work)) { ... } If we call gb_interface_release to make cleanup, there may be an unfinished work. This function will call kfree to free the object "intf". However, if gb_interface_mode_switch_work is scheduled to run after kfree, it may cause use-after-free error as gb_interface_mode_switch_work will use the object "intf". The possible execution flow that may lead to the issue is as follows: CPU0 CPU1 | gb_interface_create | gb_interface_request_mode_switch gb_interface_release | kfree(intf) (free) | | gb_interface_mode_switch_work | mutex_lock(&intf->mutex) (use) Fix it by canceling the work before kfree.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 55742d2a071a569bf20f90d37b1b5b8a25a3f882 < 74cd0a421896b2e07eafe7da4275302bfecef20174cd0a421896b2e07eafe7da4275302bfecef201
linuxlinux>= 55742d2a071a569bf20f90d37b1b5b8a25a3f882 < 2b6bb0b4abfd79b8698ee161bb73c0936a2aaf832b6bb0b4abfd79b8698ee161bb73c0936a2aaf83
linuxlinux>= 55742d2a071a569bf20f90d37b1b5b8a25a3f882 < fb071f5c75d4b1c177824de74ee75f9dd34123b9fb071f5c75d4b1c177824de74ee75f9dd34123b9
linuxlinux>= 55742d2a071a569bf20f90d37b1b5b8a25a3f882 < 9a733d69a4a59c2d08620e6589d823c24be773dc9a733d69a4a59c2d08620e6589d823c24be773dc
linuxlinux>= 55742d2a071a569bf20f90d37b1b5b8a25a3f882 < 0b8fba38bdfb848fac52e71270b2aa3538c996ea0b8fba38bdfb848fac52e71270b2aa3538c996ea
linuxlinux>= 55742d2a071a569bf20f90d37b1b5b8a25a3f882 < 03ea2b129344152157418929f06726989efc044503ea2b129344152157418929f06726989efc0445
linuxlinux>= 55742d2a071a569bf20f90d37b1b5b8a25a3f882 < 5c9c5d7f26acc2c669c1dcf57d1bb43ee99220ce5c9c5d7f26acc2c669c1dcf57d1bb43ee99220ce
linuxlinux_kernel< 5.4.2795.4.279
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 0 < 4.15.0-229.2414.15.0-229.241
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.956.1.95
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221
linuxlinux_kernel>= 6.2 < 6.6.356.6.35
linuxlinux_kernel>= 6.7 < 6.9.66.9.6
msrcazl3_kernel_6.6.22.1-2_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.