cbcvebase.
CVE-2024-41149
published 2025-01-11

CVE-2024-41149: In the Linux kernel, the following vulnerability has been resolved: block: avoid to reuse `hctx` not removed from cpuhp callback list If the 'hctx' isn't…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.3th percentile
In the Linux kernel, the following vulnerability has been resolved: block: avoid to reuse `hctx` not removed from cpuhp callback list If the 'hctx' isn't removed from cpuhp callback list, we can't reuse it, otherwise use-after-free may be triggered.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.8-1 (forky)linux 6.12.8-1 (forky)
linuxlinux>= 22465bbac53c821319089016f268a2437de9b00a < 85672ca9ceeaa1dcf2777a7048af5f4aee3fd02b85672ca9ceeaa1dcf2777a7048af5f4aee3fd02b
linuxlinux>= 58bf93580fec30d84a46be41171c5fad98b5cc70 < ee18012c80155f6809522804099621070c69ec72ee18012c80155f6809522804099621070c69ec72
linuxlinux>= 6.12.6 < 6.12.76.12.7
linuxlinux>= c1291ea131d186296dc8d328a36c3caf38e8e159 < b5792c162dcf6197bf3d2de2be6c8169435b73d0b5792c162dcf6197bf3d2de2be6c8169435b73d0
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.8-16.12.8-1
linuxlinux_kernel>= 0 < 6.12.8-16.12.8-1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.