cbcvebase.
CVE-2024-47668
published 2024-10-09

CVE-2024-47668: In the Linux kernel, the following vulnerability has been resolved: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() If we need to increase…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.17%
6.6th percentile
In the Linux kernel, the following vulnerability has been resolved: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() If we need to increase the tree depth, allocate a new node, and then race with another thread that increased the tree depth before us, we'll still have a preallocated node that might be used later. If we then use that node for a new non-root node, it'll still have a pointer to the old root instead of being zeroed - fix this by zeroing it in the cmpxchg failure path.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= ba20ba2e3743bac786dff777954c11930256075e < 0f27f4f445390cb7f73d4209cb2bf32834dc53da0f27f4f445390cb7f73d4209cb2bf32834dc53da
linuxlinux>= ba20ba2e3743bac786dff777954c11930256075e < 99418ec776a39609f50934720419e0b464ca228399418ec776a39609f50934720419e0b464ca2283
linuxlinux>= ba20ba2e3743bac786dff777954c11930256075e < ad5ee9feebc2eb8cfc76ed74a2d6e55343b0e169ad5ee9feebc2eb8cfc76ed74a2d6e55343b0e169
linuxlinux>= ba20ba2e3743bac786dff777954c11930256075e < ebeff038744c498a036e7a92eb8e433ae0a386d7ebeff038744c498a036e7a92eb8e433ae0a386d7
linuxlinux>= ba20ba2e3743bac786dff777954c11930256075e < d942e855324a60107025c116245095632476613ed942e855324a60107025c116245095632476613e
linuxlinux>= ba20ba2e3743bac786dff777954c11930256075e < 0f078f8ca93b28a34e20bd050f12cd4efeee7c0f0f078f8ca93b28a34e20bd050f12cd4efeee7c0f
linuxlinux>= ba20ba2e3743bac786dff777954c11930256075e < b2f11c6f3e1fc60742673b8675c95b78447f3daeb2f11c6f3e1fc60742673b8675c95b78447f3dae
linuxlinux_kernel< 5.4.2845.4.284
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.11 < 5.15.1675.15.167
linuxlinux_kernel>= 5.16 < 6.1.1106.1.110
linuxlinux_kernel>= 5.5 < 5.10.2265.10.226
linuxlinux_kernel>= 6.2 < 6.6.516.6.51
linuxlinux_kernel>= 6.7 < 6.10.106.10.10

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.