cbcvebase.
CVE-2024-41012
published 2024-07-23

CVE-2024-41012: In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races…

PriorityP431medium6.3CVSS 3.1
AVLACHPRLUINSUCHINAH
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it removes the created lock with do_lock_file_wait(). However, LSMs can allow the first do_lock_file_wait() that created the lock while denying the second do_lock_file_wait() that tries to remove the lock. Separately, posix_lock_file() could also fail to remove a lock due to GFP_KERNEL allocation failure (when splitting a range in the middle). After the bug has been triggered, use-after-free reads will occur in lock_get_status() when userspace reads /proc/locks. This can likely be used to read arbitrary kernel memory, but can't corrupt kernel memory. Fix it by calling locks_remove_posix() instead, which is designed to reliably get rid of POSIX locks associated with the given file and files_struct and is also used by filp_flush().

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < d30ff33040834c3b9eee29740acd92f9c7ba2250d30ff33040834c3b9eee29740acd92f9c7ba2250
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < dc2ce1dfceaa0767211a9d963ddb029ab21c4235dc2ce1dfceaa0767211a9d963ddb029ab21c4235
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < 5661b9c7ec189406c2dde00837aaa4672efb62405661b9c7ec189406c2dde00837aaa4672efb6240
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < 52c87ab18c76c14d7209646ccb3283b3f5d87b2252c87ab18c76c14d7209646ccb3283b3f5d87b22
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < ef8fc41cd6f95f9a4a3470f085aecf350569a0b3ef8fc41cd6f95f9a4a3470f085aecf350569a0b3
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < 5f5d0799eb0a01d550c21b7894e26b2d9db557635f5d0799eb0a01d550c21b7894e26b2d9db55763
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < b6d223942c34057fdfd8f149e763fa823731b224b6d223942c34057fdfd8f149e763fa823731b224
linuxlinux>= c293621bbf678a3d85e3ed721c3921c8a670610d < 3cad1bc010416c6dd780643476bc59ed742436b93cad1bc010416c6dd780643476bc59ed742436b9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 0 < 4.4.0-263.2974.4.0-263.297
linuxlinux_kernel>= 0 < 4.15.0-233.2454.15.0-233.245
linuxlinux_kernel>= 2.6.13 < 4.19.3194.19.319
linuxlinux_kernel>= 4.20 < 5.4.2815.4.281
linuxlinux_kernel>= 5.11 < 5.15.1645.15.164
linuxlinux_kernel>= 5.16 < 6.1.1016.1.101

CVSS provenance

nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.