cbcvebase.
CVE-2024-43849
published 2024-08-17

CVE-2024-43849: In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pdr: protect locator_addr with the main mutex If the service locator server is…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.16%
6.0th percentile
In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pdr: protect locator_addr with the main mutex If the service locator server is restarted fast enough, the PDR can rewrite locator_addr fields concurrently. Protect them by placing modification of those fields under the main pdr->lock.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= fbe639b44a82755d639df1c5d147c93f02ac5a0f < eab05737ee22216250fe20d27f5a596da5ea6eb7eab05737ee22216250fe20d27f5a596da5ea6eb7
linuxlinux>= fbe639b44a82755d639df1c5d147c93f02ac5a0f < d0870c4847e77a49c2f91bb2a8e0fa3c1f8dea5cd0870c4847e77a49c2f91bb2a8e0fa3c1f8dea5c
linuxlinux>= fbe639b44a82755d639df1c5d147c93f02ac5a0f < 475a77fb3f0e1d527f56c60b79f5879661df5b80475a77fb3f0e1d527f56c60b79f5879661df5b80
linuxlinux>= fbe639b44a82755d639df1c5d147c93f02ac5a0f < 3e815626d73e05152a8142f6e44aecc4133e6e083e815626d73e05152a8142f6e44aecc4133e6e08
linuxlinux>= fbe639b44a82755d639df1c5d147c93f02ac5a0f < 8543269567e2fb3d976a8255c5e348aed14f98bc8543269567e2fb3d976a8255c5e348aed14f98bc
linuxlinux>= fbe639b44a82755d639df1c5d147c93f02ac5a0f < 107924c14e3ddd85119ca43c26a4ee1056fa9b84107924c14e3ddd85119ca43c26a4ee1056fa9b84
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.7 < 6.1.1036.1.103
linuxlinux_kernel>= 6.2 < 6.6.446.6.44
linuxlinux_kernel>= 6.7 < 6.10.36.10.3
msrccbl2_kernel_5.15.176.3-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.