cbcvebase.
CVE-2024-50080
published 2024-10-29

CVE-2024-50080: In the Linux kernel, the following vulnerability has been resolved: ublk: don't allow user copy for unprivileged device UBLK_F_USER_COPY requires userspace to…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
10.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ublk: don't allow user copy for unprivileged device UBLK_F_USER_COPY requires userspace to call write() on ublk char device for filling request buffer, and unprivileged device can't be trusted. So don't allow user copy for unprivileged device.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.11.5-1 (forky)linux 6.11.5-1 (forky)
linuxlinux
linuxlinux>= 1172d5b8beca6b899deb9f7f2850e7e47ec16198 < 6414ab5c9c9c068eca6dc4fd3a036bc4b83164dc6414ab5c9c9c068eca6dc4fd3a036bc4b83164dc
linuxlinux>= 1172d5b8beca6b899deb9f7f2850e7e47ec16198 < 8f3d5686a2409877c5e8e2540774d24ed2b4a4ce8f3d5686a2409877c5e8e2540774d24ed2b4a4ce
linuxlinux>= 1172d5b8beca6b899deb9f7f2850e7e47ec16198 < 42aafd8b48adac1c3b20fe5892b1b91b80c1a1e642aafd8b48adac1c3b20fe5892b1b91b80c1a1e6
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 6.8.0-56.586.8.0-56.58
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.5 < 6.6.586.6.58
linuxlinux_kernel>= 6.7 < 6.11.56.11.5
msrcazl3_kernel_6.6.57.1-7_on_azure_linux_3.0
msrcazl3_kernel_6.6.64.2-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.