cbcvebase.
CVE-2024-42285
published 2024-08-17

CVE-2024-42285: In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix a use-after-free related to destroying CM IDs iw_conn_req_handler()…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.7th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix a use-after-free related to destroying CM IDs iw_conn_req_handler() associates a new struct rdma_id_private (conn_id) with an existing struct iw_cm_id (cm_id) as follows: conn_id->cm_id.iw = cm_id; cm_id->context = conn_id; cm_id->cm_handler = cma_iw_handler; rdma_destroy_id() frees both the cm_id and the struct rdma_id_private. Make sure that cm_work_handler() does not trigger a use-after-free by only freeing of the struct rdma_id_private after all pending work has finished.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 59c68ac31e15ad09d2cb04734e3c8c544a95f8d4 < d91d253c87fd1efece521ff2612078a35af673c6d91d253c87fd1efece521ff2612078a35af673c6
linuxlinux>= 59c68ac31e15ad09d2cb04734e3c8c544a95f8d4 < 7f25f296fc9bd0435be14e89bf657cd615a235747f25f296fc9bd0435be14e89bf657cd615a23574
linuxlinux>= 59c68ac31e15ad09d2cb04734e3c8c544a95f8d4 < 94ee7ff99b87435ec63211f632918dc7f44dac7994ee7ff99b87435ec63211f632918dc7f44dac79
linuxlinux>= 59c68ac31e15ad09d2cb04734e3c8c544a95f8d4 < 557d035fe88d78dd51664f4dc0e1896c04c97cf6557d035fe88d78dd51664f4dc0e1896c04c97cf6
linuxlinux>= 59c68ac31e15ad09d2cb04734e3c8c544a95f8d4 < dc8074b8901caabb97c2d353abd6b4e7fa5a59a5dc8074b8901caabb97c2d353abd6b4e7fa5a59a5
linuxlinux>= 59c68ac31e15ad09d2cb04734e3c8c544a95f8d4 < ff5bbbdee08287d75d72e65b72a2b76d9637892aff5bbbdee08287d75d72e65b72a2b76d9637892a
linuxlinux>= 59c68ac31e15ad09d2cb04734e3c8c544a95f8d4 < ee39384ee787e86e9db4efb843818ef0ea9cb8aeee39384ee787e86e9db4efb843818ef0ea9cb8ae
linuxlinux>= 59c68ac31e15ad09d2cb04734e3c8c544a95f8d4 < aee2424246f9f1dadc33faa78990c1e2eb7826e4aee2424246f9f1dadc33faa78990c1e2eb7826e4
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 4.20 < 5.4.2825.4.282
linuxlinux_kernel>= 4.8 < 4.19.3204.19.320
linuxlinux_kernel>= 5.11 < 5.15.1655.15.165
linuxlinux_kernel>= 5.16 < 6.1.1036.1.103
linuxlinux_kernel>= 5.5 < 5.10.2245.10.224
linuxlinux_kernel>= 6.2 < 6.6.446.6.44
linuxlinux_kernel>= 6.7 < 6.10.36.10.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.