cbcvebase.
CVE-2024-43883
published 2024-08-23

CVE-2024-43883: In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places the…

PriorityP429high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places the driver carries stale pointers to references that can still be used. Make sure that does not happen. This strictly speaking closes ZDI-CAN-22273, though there may be similar races in the driver.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 2.6.32.30 < 2.6.332.6.33
linuxlinux>= 2.6.33.8 < 2.6.342.6.34
linuxlinux>= 2.6.34.10 < 2.6.352.6.35
linuxlinux>= 2.6.35.12 < 2.6.362.6.36
linuxlinux>= 2.6.37.3 < 2.6.382.6.38
linuxlinux>= 7606ee8aa33287dd3e6eb44c78541b87a413a325 < 5a3c473b28ae1c1f7c4dc129e30cb19ae6e96f895a3c473b28ae1c1f7c4dc129e30cb19ae6e96f89
linuxlinux>= 7606ee8aa33287dd3e6eb44c78541b87a413a325 < 9c3746ce8d8fcb3a2405644fc0eec7fc5312de809c3746ce8d8fcb3a2405644fc0eec7fc5312de80
linuxlinux>= 7606ee8aa33287dd3e6eb44c78541b87a413a325 < 4dacdb9720aaab10b6be121eae55820174d971744dacdb9720aaab10b6be121eae55820174d97174
linuxlinux>= 7606ee8aa33287dd3e6eb44c78541b87a413a325 < e8c1e606dab8c56cf074b43b98d0805de7322ba2e8c1e606dab8c56cf074b43b98d0805de7322ba2
linuxlinux>= 7606ee8aa33287dd3e6eb44c78541b87a413a325 < 585e6bc7d0a9bf73a8be3d3fb34e86b90cc61a14585e6bc7d0a9bf73a8be3d3fb34e86b90cc61a14
linuxlinux>= 7606ee8aa33287dd3e6eb44c78541b87a413a325 < 128e82e41cf7d74a562726c1587d9d2ede1a0a37128e82e41cf7d74a562726c1587d9d2ede1a0a37
linuxlinux>= 7606ee8aa33287dd3e6eb44c78541b87a413a325 < c3d0857b7fc2c49f68f89128a5440176089a8f54c3d0857b7fc2c49f68f89128a5440176089a8f54
linuxlinux>= 7606ee8aa33287dd3e6eb44c78541b87a413a325 < afdcfd3d6fcdeca2735ca8d994c5f2d24a368f0aafdcfd3d6fcdeca2735ca8d994c5f2d24a368f0a
linuxlinux_kernel< 4.19.3204.19.320
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.