cbcvebase.
CVE-2024-53057
published 2024-11-19

CVE-2024-53057: In the Linux kernel, the following vulnerability has been resolved: net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT In qdisc_tree_reduce_backlog, Qdiscs…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.5th percentile
In the Linux kernel, the following vulnerability has been resolved: net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT In qdisc_tree_reduce_backlog, Qdiscs with major handle ffff: are assumed to be either root or ingress. This assumption is bogus since it's valid to create egress qdiscs with major handle ffff: Budimir Markovic found that for qdiscs like DRR that maintain an active class list, it will cause a UAF with a dangling class pointer. In 066a3b5b2346, the concern was to avoid iterating over the ingress qdisc since its parent is itself. The proper fix is to stop when parent TC_H_ROOT is reached because the only way to retrieve ingress is when a hierarchy which does not contain a ffff: major handle call into qdisc_lookup with TC_H_MAJ(TC_H_ROOT). In the scenario where major ffff: is an egress qdisc in any of the tree levels, the updates will also propagate to TC_H_ROOT, which then the iteration must stop. net/sched/sch_api.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
googlechrome_chrome
linuxlinux
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < e7f9a6f97eb067599a74f3bcb6761976b0ed303ee7f9a6f97eb067599a74f3bcb6761976b0ed303e
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < dbe778b08b5101df9e89bc06e0a3a7ecd2f4ef20dbe778b08b5101df9e89bc06e0a3a7ecd2f4ef20
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < ce691c814bc7a3c30c220ffb5b7422715458fd9bce691c814bc7a3c30c220ffb5b7422715458fd9b
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < 05df1b1dff8f197f1c275b57ccb2ca33021df55205df1b1dff8f197f1c275b57ccb2ca33021df552
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < 580b3189c1972aff0f993837567d36392e9d981b580b3189c1972aff0f993837567d36392e9d981b
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < 597cf9748c3477bf61bc35f0634129f56764ad24597cf9748c3477bf61bc35f0634129f56764ad24
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < 9995909615c3431a5304c1210face5f268d24dba9995909615c3431a5304c1210face5f268d24dba
linuxlinux>= 066a3b5b2346febf9a655b444567b7138e3bb939 < 2e95c4384438adeaa772caa560244b1a2efef8162e95c4384438adeaa772caa560244b1a2efef816
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.7-16.11.7-1
linuxlinux_kernel>= 0 < 6.11.7-16.11.7-1
linuxlinux_kernel>= 0 < 5.4.0-204.2245.4.0-204.224
linuxlinux_kernel>= 0 < 5.15.0-130.1405.15.0-130.140
linuxlinux_kernel>= 0 < 6.8.0-51.526.8.0-51.52
linuxlinux_kernel>= 0 < 6.11.0-13.146.11.0-13.14
linuxlinux_kernel>= 0 < 4.4.0-262.2964.4.0-262.296
linuxlinux_kernel>= 0 < 4.15.0-232.2444.15.0-232.244
linuxlinux_kernel>= 2.6.25 < 4.19.3234.19.323
linuxlinux_kernel>= 4.20 < 5.4.2855.4.285

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.