cbcvebase.
CVE-2024-50267
published 2024-11-19

CVE-2024-50267: In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_edgeport: fix use after free in debug printk The "dev_dbg(&urb->dev->dev…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.7th percentile
In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_edgeport: fix use after free in debug printk The "dev_dbg(&urb->dev->dev, ..." which happens after usb_free_urb(urb) is a use after free of the "urb" pointer. Store the "dev" pointer at the start of the function to avoid this issue.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= 984f68683298ba53af32f909de1f9452fbb37ccb < e6ceb04eeb6115d872d4c4078d12f1170ed755cee6ceb04eeb6115d872d4c4078d12f1170ed755ce
linuxlinux>= 984f68683298ba53af32f909de1f9452fbb37ccb < 39709ce93f5c3f9eb535efe2afea088805d1128f39709ce93f5c3f9eb535efe2afea088805d1128f
linuxlinux>= 984f68683298ba53af32f909de1f9452fbb37ccb < e567fc8f7a4460e486e52c9261b1e8b9f5dc42aae567fc8f7a4460e486e52c9261b1e8b9f5dc42aa
linuxlinux>= 984f68683298ba53af32f909de1f9452fbb37ccb < 44fff2c16c5aafbdb70c7183dae0a415ae74705e44fff2c16c5aafbdb70c7183dae0a415ae74705e
linuxlinux>= 984f68683298ba53af32f909de1f9452fbb37ccb < 275258c30bbda29467216e96fb655b16bcc9992b275258c30bbda29467216e96fb655b16bcc9992b
linuxlinux>= 984f68683298ba53af32f909de1f9452fbb37ccb < 13d6ff3ca76056d06a9d88300be2a293442ff59513d6ff3ca76056d06a9d88300be2a293442ff595
linuxlinux>= 984f68683298ba53af32f909de1f9452fbb37ccb < 314bdf446053e123f37543aa535197ee75f8aa97314bdf446053e123f37543aa535197ee75f8aa97
linuxlinux>= 984f68683298ba53af32f909de1f9452fbb37ccb < 37bb5628379295c1254c113a407cab03a0f4d0b437bb5628379295c1254c113a407cab03a0f4d0b4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 3.7 < 4.19.3244.19.324
linuxlinux_kernel>= 4.20 < 5.4.2865.4.286
linuxlinux_kernel>= 5.11 < 5.15.1725.15.172
linuxlinux_kernel>= 5.16 < 6.1.1176.1.117
linuxlinux_kernel>= 5.5 < 5.10.2305.10.230

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.