cbcvebase.
CVE-2024-50051
published 2025-01-11

CVE-2024-50051: In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: Add cancel_work_sync before module remove If we remove the module which will…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.5th percentile
In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: Add cancel_work_sync before module remove If we remove the module which will call mpc52xx_spi_remove it will free 'ms' through spi_unregister_controller. while the work ms->work will be used. The sequence of operations that may lead to a UAF bug. Fix it by ensuring that the work is canceled before proceeding with the cleanup in mpc52xx_spi_remove.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= ca632f556697d45d67ed5cada7cedf3ddfe0db4b < d0cde3911cf24e1bcdd4caa1d1b9ef57589db5a1d0cde3911cf24e1bcdd4caa1d1b9ef57589db5a1
linuxlinux>= ca632f556697d45d67ed5cada7cedf3ddfe0db4b < e0c6ce8424095c2da32a063d3fc027494c689817e0c6ce8424095c2da32a063d3fc027494c689817
linuxlinux>= ca632f556697d45d67ed5cada7cedf3ddfe0db4b < cd5106c77d6d6828aa82449f01f4eb436d602a21cd5106c77d6d6828aa82449f01f4eb436d602a21
linuxlinux>= ca632f556697d45d67ed5cada7cedf3ddfe0db4b < 373d55a47dc662e5e30d12ad5d334312f757c1f1373d55a47dc662e5e30d12ad5d334312f757c1f1
linuxlinux>= ca632f556697d45d67ed5cada7cedf3ddfe0db4b < f65d85bc1ffd8a2c194bb2cd65e35ed3648ddd59f65d85bc1ffd8a2c194bb2cd65e35ed3648ddd59
linuxlinux>= ca632f556697d45d67ed5cada7cedf3ddfe0db4b < 90b72189de2cddacb26250579da0510b29a8b82b90b72189de2cddacb26250579da0510b29a8b82b
linuxlinux>= ca632f556697d45d67ed5cada7cedf3ddfe0db4b < 984836621aad98802d92c4a3047114cf518074c8984836621aad98802d92c4a3047114cf518074c8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 4.4.0-272.3064.4.0-272.306
linuxlinux_kernel>= 0 < 4.15.0-241.2534.15.0-241.253
linuxlinux_kernel>= 3.1 < 5.4.2875.4.287
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231
linuxlinux_kernel>= 6.2 < 6.6.666.6.66
linuxlinux_kernel>= 6.7 < 6.12.56.12.5

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.