cbcvebase.
CVE-2024-45007
published 2024-09-04

CVE-2024-45007: In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Don't destroy workqueue from work item running on it Triggered by a kref…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Don't destroy workqueue from work item running on it Triggered by a kref decrement, destroy_workqueue() may be called from within a work item for destroying its own workqueue. This illegal situation is averted by adding a module-global workqueue for exclusive use of the offending work item. Other work items continue to be queued on per-device workqueues to ensure performance.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= a53d1202aef122894b6e46116a92174a9123db5d < 409b495f8e3300d5fba08bc817fa8825dae48cc9409b495f8e3300d5fba08bc817fa8825dae48cc9
linuxlinux>= a53d1202aef122894b6e46116a92174a9123db5d < 5d3567caff2a1d678aa40cc74a54e1318941fad35d3567caff2a1d678aa40cc74a54e1318941fad3
linuxlinux>= a53d1202aef122894b6e46116a92174a9123db5d < a7ad105b12256ec7fb6d6d1a0e2e60f00b7da157a7ad105b12256ec7fb6d6d1a0e2e60f00b7da157
linuxlinux>= a53d1202aef122894b6e46116a92174a9123db5d < aa1a19724fa2c31e97a9be48baedd4692b265157aa1a19724fa2c31e97a9be48baedd4692b265157
linuxlinux>= a53d1202aef122894b6e46116a92174a9123db5d < ccbde4b128ef9c73d14d0d7817d68ef795f6d131ccbde4b128ef9c73d14d0d7817d68ef795f6d131
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.14 < 5.15.1665.15.166
linuxlinux_kernel>= 5.16 < 6.1.1076.1.107
linuxlinux_kernel>= 6.2 < 6.6.486.6.48
linuxlinux_kernel>= 6.7 < 6.10.76.10.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.