cbcvebase.
CVE-2024-41049
published 2024-07-29

CVE-2024-41049: In the Linux kernel, the following vulnerability has been resolved: filelock: fix potential use-after-free in posix_lock_inode Light Hsieh reported a KASAN UAF…

PriorityP429high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.26%
17.7th percentile
In the Linux kernel, the following vulnerability has been resolved: filelock: fix potential use-after-free in posix_lock_inode Light Hsieh reported a KASAN UAF warning in trace_posix_lock_inode(). The request pointer had been changed earlier to point to a lock entry that was added to the inode's list. However, before the tracepoint could fire, another task raced in and freed that lock. Fix this by moving the tracepoint inside the spinlock, which should ensure that this doesn't happen.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 117fb80cd1e63c419c7a221ce070becb4bfc7b6d < 1cbbb3d9475c403ebedc327490c7c2b9913981971cbbb3d9475c403ebedc327490c7c2b991398197
linuxlinux>= 34bff6d850019e00001129d6de3aa4874c2cf471 < 5cb36e35bc10ea334810937990c2b9023dacb1b05cb36e35bc10ea334810937990c2b9023dacb1b0
linuxlinux>= 5.10.197 < 5.10.2225.10.222
linuxlinux>= 5.15.133 < 5.15.1635.15.163
linuxlinux>= 5.4.257 < 5.4.2805.4.280
linuxlinux>= 6.1.55 < 6.1.1006.1.100
linuxlinux>= 6.5.5 < 6.66.6
linuxlinux>= 74f6f5912693ce454384eaeec48705646a21c74f < 432b06b69d1d354a171f7499141116536579eb6a432b06b69d1d354a171f7499141116536579eb6a
linuxlinux>= 74f6f5912693ce454384eaeec48705646a21c74f < 116599f6a26906cf33f67975c59f0692ecf7e9b2116599f6a26906cf33f67975c59f0692ecf7e9b2
linuxlinux>= 74f6f5912693ce454384eaeec48705646a21c74f < 1b3ec4f7c03d4b07bad70697d7e2f4088d2cfe921b3ec4f7c03d4b07bad70697d7e2f4088d2cfe92
linuxlinux>= 766e56faddbec2eaf70c9299e1c9ef74d846d32b < 02a8964260756c70b20393ad4006948510ac996702a8964260756c70b20393ad4006948510ac9967
linuxlinux>= a6f4129378ca15f62cbdde09a7d3ccc35adcf49d < 7d4c14f4b511fd4c0dc788084ae59b4656ace58b7d4c14f4b511fd4c0dc788084ae59b4656ace58b
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.10.197 < 5.10.2225.10.222
linuxlinux_kernel>= 5.15.133 < 5.15.1635.15.163

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_msrc7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.