cbcvebase.
CVE-2024-50264
published 2024-11-19

CVE-2024-50264: In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans During…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.35%
28.0th percentile
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans During loopback communication, a dangling pointer can be created in vsk->trans, potentially leading to a Use-After-Free condition. This issue is resolved by initializing vsk->trans to NULL.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
googleandroid
googlechrome_chrome
linuxlinux
linuxlinux>= 06a8fc78367d070720af960dcecec917d3ae5f3b < 5f092a4271f6dccf88fe0d132475a17b69ef71df5f092a4271f6dccf88fe0d132475a17b69ef71df
linuxlinux>= 06a8fc78367d070720af960dcecec917d3ae5f3b < fd8ae346692a56b4437d626c5460c7104980f389fd8ae346692a56b4437d626c5460c7104980f389
linuxlinux>= 06a8fc78367d070720af960dcecec917d3ae5f3b < eb1bdcb7dfc30b24495ee4c5533af0ed135cb5f1eb1bdcb7dfc30b24495ee4c5533af0ed135cb5f1
linuxlinux>= 06a8fc78367d070720af960dcecec917d3ae5f3b < 2a6a4e69f255b7aed17f93995691ab4f0d3c22032a6a4e69f255b7aed17f93995691ab4f0d3c2203
linuxlinux>= 06a8fc78367d070720af960dcecec917d3ae5f3b < 44d29897eafd0e1196453d3003a4d5e0b968eeab44d29897eafd0e1196453d3003a4d5e0b968eeab
linuxlinux>= 06a8fc78367d070720af960dcecec917d3ae5f3b < b110196fec44fe966952004bd426967c2a8fd358b110196fec44fe966952004bd426967c2a8fd358
linuxlinux>= 06a8fc78367d070720af960dcecec917d3ae5f3b < 5f970935d09934222fdef3d0e20c648ea7a963c15f970935d09934222fdef3d0e20c648ea7a963c1
linuxlinux>= 06a8fc78367d070720af960dcecec917d3ae5f3b < 6ca575374dd9a507cdd16dfa0e78c2e9e20bd05f6ca575374dd9a507cdd16dfa0e78c2e9e20bd05f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 5.4.0-204.2245.4.0-204.224
linuxlinux_kernel>= 0 < 5.15.0-130.1405.15.0-130.140
linuxlinux_kernel>= 0 < 6.8.0-51.526.8.0-51.52
linuxlinux_kernel>= 0 < 6.11.0-13.146.11.0-13.14
linuxlinux_kernel>= 0 < 4.4.0-267.3014.4.0-267.301
linuxlinux_kernel>= 0 < 4.15.0-233.2454.15.0-233.245
linuxlinux_kernel>= 0 < 4.15.0-232.2444.15.0-232.244

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.