cbcvebase.
CVE-2024-41075
published 2024-07-29

CVE-2024-41075: In the Linux kernel, the following vulnerability has been resolved: cachefiles: add consistency check for copen/cread This prevents malicious processes from…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.5th percentile
In the Linux kernel, the following vulnerability has been resolved:

cachefiles: add consistency check for copen/cread

This prevents malicious processes from completing random copen/cread
requests and crashing the system. Added checks are listed below:

* Generic, copen can only complete open requests, and cread can only
complete read requests.
* For copen, ondemand_id must not be 0, because this indicates that the
request has not been read by the daemon.
* For cread, the object corresponding to fd and req should be the same.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 9032b6e8589f269743984aac53e82e4835be16dc < 3b744884c0431b5a62c92900e64bfd0ed61e8e2a3b744884c0431b5a62c92900e64bfd0ed61e8e2a
linuxlinux>= 9032b6e8589f269743984aac53e82e4835be16dc < 36d845ccd7bf527110a65fe953886a176c20953936d845ccd7bf527110a65fe953886a176c209539
linuxlinux>= 9032b6e8589f269743984aac53e82e4835be16dc < 8aaa6c5dd2940ab934d6cd296175f43dbb32b34a8aaa6c5dd2940ab934d6cd296175f43dbb32b34a
linuxlinux>= 9032b6e8589f269743984aac53e82e4835be16dc < a26dc49df37e996876f50a0210039b2d211fdd6fa26dc49df37e996876f50a0210039b2d211fdd6f
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.9.11-16.9.11-1
linuxlinux_kernel>= 0 < 6.9.11-16.9.11-1
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.19 < 6.1.1016.1.101
linuxlinux_kernel>= 6.2 < 6.6.426.6.42
linuxlinux_kernel>= 6.7 < 6.9.116.9.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.