cbcvebase.
CVE-2024-44959
published 2024-09-04

CVE-2024-44959: In the Linux kernel, the following vulnerability has been resolved: tracefs: Use generic inode RCU for synchronizing freeing With structure layout…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.7th percentile
In the Linux kernel, the following vulnerability has been resolved: tracefs: Use generic inode RCU for synchronizing freeing With structure layout randomization enabled for 'struct inode' we need to avoid overlapping any of the RCU-used / initialized-only-once members, e.g. i_lru or i_sb_list to not corrupt related list traversals when making use of the rcu_head. For an unlucky structure layout of 'struct inode' we may end up with the following splat when running the ftrace selftests: [] list_del corruption, ffff888103ee2cb0->next (tracefs_inode_cache+0x0/0x4e0 [slab object]) is NULL (prev is tracefs_inode_cache+0x78/0x4e0 [slab object]) [] ------------[ cut here ]------------ [] kernel BUG at lib/list_debug.c:54! [] invalid opcode: 0000 [#1] PREEMPT SMP KASAN [] CPU: 3 PID: 2550 Comm: mount Tainted: G N 6.8.12-grsec+ #122 ed2f536ca62f28b087b90e3cc906a8d25b3ddc65 [] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014 [] RIP: 0010:[] __list_del_entry_valid_or_report+0x138/0x3e0 [] Code: 48 b8 99 fb 65 f2 ff ff ff ff e9 03 5c d9 fc cc 48 b8 99 fb 65 f2 ff ff ff ff e9 33 5a d9 fc cc 48 b8 99 fb 65 f2 ff ff ff ff 0b 4c 89 e9 48 89 ea 48 89 ee 48 c7 c7 60 8f dd 89 31 c0 e8 2f [] RSP: 0018:fffffe80416afaf0 EFLAGS: 00010283 [] RAX: 0000000000000098 RBX: ffff888103ee2cb0 RCX: 0000000000000000 [] RDX: ffffffff84655fe8 RSI: ffffffff89dd8b60 RDI: 0000000000000001 [] RBP: ffff888103ee2cb0 R08: 0000000000000001 R09: fffffbd0082d5f25 [] R10: fffffe80416af92f R11: 0000000000000001 R12: fdf99c16731d9b6d [] R13: 0000000000000000 R14: ffff88819ad4b8b8 R15: 0000000000000000 [] RBX: tracefs_inode_cache+0x0/0x4e0 [slab object] [] RDX: __list_del_entry_valid_or_report+0x108/0x3e0 [] RSI: __func__.47+0x4340/0x4400 [] RBP: tracefs_inode_cache+0x0/0x4e0 [slab object] [] RSP: process kstack fffffe80416afaf0+0x7af0/0x8000 [mount 2550 2550] [] R09: kasan shadow of process kstack fffffe80416af928+0x7928/0x8000 [mount 2550 2550] [] R10: process kstack fffffe80416a

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.10.6-1 (forky)linux 6.10.6-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 5f91fc82794d4a6e41cdcd02d00baa377d94ca78 < 726f4c241e17be75a9cf6870d80cd7479dc89e8f726f4c241e17be75a9cf6870d80cd7479dc89e8f
linuxlinux>= 6.6.31 < 6.6.466.6.46
linuxlinux>= 6.8.10 < 6.96.9
linuxlinux>= baa23a8d4360d981a49913841a726edede5cdd54 < 061da60716ce0cde99f62f31937b81e1c03acef6061da60716ce0cde99f62f31937b81e1c03acef6
linuxlinux>= baa23a8d4360d981a49913841a726edede5cdd54 < 0b6743bd60a56a701070b89fb80c327a44b7b3e20b6743bd60a56a701070b89fb80c327a44b7b3e2
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 6.6.31 < 6.6.466.6.46
linuxlinux_kernel>= 6.8.10 < 6.96.9
linuxlinux_kernel>= 6.9 < 6.10.56.10.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.