cbcvebase.
CVE-2024-49954
published 2024-10-21

CVE-2024-49954: In the Linux kernel, the following vulnerability has been resolved: static_call: Replace pointless WARN_ON() in static_call_module_notify()…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved: static_call: Replace pointless WARN_ON() in static_call_module_notify() static_call_module_notify() triggers a WARN_ON(), when memory allocation fails in __static_call_add_module(). That's not really justified, because the failure case must be correctly handled by the well known call chain and the error code is passed through to the initiating userspace application. A memory allocation fail is not a fatal problem, but the WARN_ON() takes the machine out when panic_on_warn is set. Replace it with a pr_warn().

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 9183c3f9ed710a8edf1a61e8a96d497258d26e08 < bc9356513d56b688775497b7ac6f2b967f46a80cbc9356513d56b688775497b7ac6f2b967f46a80c
linuxlinux>= 9183c3f9ed710a8edf1a61e8a96d497258d26e08 < ea2cdf4da093d0482f0ef36ba971e2e0c7673425ea2cdf4da093d0482f0ef36ba971e2e0c7673425
linuxlinux>= 9183c3f9ed710a8edf1a61e8a96d497258d26e08 < e67534bd31d79952b50e791e92adf0b3e6c13b8ce67534bd31d79952b50e791e92adf0b3e6c13b8c
linuxlinux>= 9183c3f9ed710a8edf1a61e8a96d497258d26e08 < 85a104aaef1f56623acc10ba4c42d5f046ba65b785a104aaef1f56623acc10ba4c42d5f046ba65b7
linuxlinux>= 9183c3f9ed710a8edf1a61e8a96d497258d26e08 < b83bef74c121a3311240fc4002d23486b85355e4b83bef74c121a3311240fc4002d23486b85355e4
linuxlinux>= 9183c3f9ed710a8edf1a61e8a96d497258d26e08 < fe513c2ef0a172a58f158e2e70465c4317f0a9a2fe513c2ef0a172a58f158e2e70465c4317f0a9a2
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.10 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113
linuxlinux_kernel>= 6.11 < 6.11.36.11.3
linuxlinux_kernel>= 6.2 < 6.6.556.6.55
linuxlinux_kernel>= 6.7 < 6.10.146.10.14
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.57.1-2_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_kernel_5.15.167.1-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.