cbcvebase.
CVE-2024-49975
published 2024-10-21

CVE-2024-49975: In the Linux kernel, the following vulnerability has been resolved: uprobes: fix kernel info leak via "[uprobes]" vma xol_add_vma() maps the uninitialized page…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.3th percentile
In the Linux kernel, the following vulnerability has been resolved: uprobes: fix kernel info leak via "[uprobes]" vma xol_add_vma() maps the uninitialized page allocated by __create_xol_area() into userspace. On some architectures (x86) this memory is readable even without VM_READ, VM_EXEC results in the same pgprot_t as VM_EXEC|VM_READ, although this doesn't really matter, debugger can read this memory anyway.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= d4b3b6384f98f8692ad0209891ccdbc7e78bbefe < f31f92107e5a8ecc8902705122c594e979a351fef31f92107e5a8ecc8902705122c594e979a351fe
linuxlinux>= d4b3b6384f98f8692ad0209891ccdbc7e78bbefe < fe5e9182d3e227476642ae2b312e2356c4d326a3fe5e9182d3e227476642ae2b312e2356c4d326a3
linuxlinux>= d4b3b6384f98f8692ad0209891ccdbc7e78bbefe < f561b48d633ac2e7d0d667020fc634a96ade33a0f561b48d633ac2e7d0d667020fc634a96ade33a0
linuxlinux>= d4b3b6384f98f8692ad0209891ccdbc7e78bbefe < 21cb47db1ec9765f91304763a24565ddc22d249221cb47db1ec9765f91304763a24565ddc22d2492
linuxlinux>= d4b3b6384f98f8692ad0209891ccdbc7e78bbefe < 24141df5a8615790950deedd926a44ddf1dfd6d824141df5a8615790950deedd926a44ddf1dfd6d8
linuxlinux>= d4b3b6384f98f8692ad0209891ccdbc7e78bbefe < 5b981d8335e18aef7908a068529a3287258ff6d85b981d8335e18aef7908a068529a3287258ff6d8
linuxlinux>= d4b3b6384f98f8692ad0209891ccdbc7e78bbefe < 2aa45f43709ba2082917bd2973d02687075b6eee2aa45f43709ba2082917bd2973d02687075b6eee
linuxlinux>= d4b3b6384f98f8692ad0209891ccdbc7e78bbefe < 9634e8dc964a4adafa7e1535147abd7ec29441a69634e8dc964a4adafa7e1535147abd7ec29441a6
linuxlinux>= d4b3b6384f98f8692ad0209891ccdbc7e78bbefe < 34820304cc2cd1804ee1f8f3504ec77813d29c8e34820304cc2cd1804ee1f8f3504ec77813d29c8e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 3.5 < 5.10.2275.10.227
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113
linuxlinux_kernel>= 6.11 < 6.11.36.11.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.