cbcvebase.
CVE-2024-50174
published 2024-11-08

CVE-2024-50174: In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix race when converting group handle to group object XArray provides it's own…

PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.20%
10.0th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix race when converting group handle to group object XArray provides it's own internal lock which protects the internal array when entries are being simultaneously added and removed. However there is still a race between retrieving the pointer from the XArray and incrementing the reference count. To avoid this race simply hold the internal XArray lock when incrementing the reference count, this ensures there cannot be a racing call to xa_erase().

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.11.4-1 (forky)linux 6.11.4-1 (forky)
linuxlinux
linuxlinux>= de85488138247d034eb3241840424a54d660926b < 8a585d553c11965332d7a2d74e79ef92a42bfc878a585d553c11965332d7a2d74e79ef92a42bfc87
linuxlinux>= de85488138247d034eb3241840424a54d660926b < 44742138d151c3a945460ae7beff8ae45ac0bf5844742138d151c3a945460ae7beff8ae45ac0bf58
linuxlinux>= de85488138247d034eb3241840424a54d660926b < cac075706f298948898b1f63e81709df42afa75dcac075706f298948898b1f63e81709df42afa75d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.10 < 6.10.146.10.14
linuxlinux_kernel>= 6.11 < 6.11.36.11.3

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.