CVE-2024-41012Use After Free in Linux

CWE-416Use After Free58 documents7 sources
Severity
6.3MEDIUMNVD
OSV8.8OSV7.1OSV5.5
EPSS
0.0%
top 98.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateAug 14

Description

In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it removes the created lock with do_lock_file_wait(). However, LSMs can allow the first do_lock_file_wait() that created the lock while denying the second do_lock_file_wait() that tries to remove the lock. Separately, posix_lock_file() could also fail to remove a lock due to GFP_KERNEL allocation failure (when splitting a r

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.0 | Impact: 5.2

Affected Packages6 packages

NVDlinux/linux_kernel2.6.134.19.319+7
Debianlinux/linux_kernel< 5.10.223-1+3
Ubuntulinux/linux_kernel< 5.4.0-200.220+4
CVEListV5linux/linuxc293621bbf678a3d85e3ed721c3921c8a670610dd30ff33040834c3b9eee29740acd92f9c7ba2250+8
debiandebian/linux< linux 6.1.106-1 (bookworm)

Patches

🔴Vulnerability Details

28
OSV
linux-kvm vulnerabilities2025-02-24
OSV
linux, linux-aws, linux-lts-xenial vulnerabilities2025-02-10
OSV
linux-azure vulnerabilities2025-02-03
OSV
linux-azure, linux-azure-4.15 vulnerabilities2025-01-30
OSV
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities2025-01-28

📋Vendor Advisories

29
CISA ICS
Siemens Third-Party Components in SINEC OS2025-08-14
Ubuntu
Linux kernel (KVM) vulnerabilities2025-02-24
Ubuntu
Linux kernel vulnerabilities2025-02-10
Ubuntu
Linux kernel (Azure) vulnerabilities2025-02-03
Ubuntu
Linux kernel (Azure) vulnerabilities2025-01-30