cbcvebase.
CVE-2024-53109
published 2024-12-02

CVE-2024-53109: In the Linux kernel, the following vulnerability has been resolved: nommu: pass NULL argument to vma_iter_prealloc() When deleting a vma entry from a maple…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.2th percentile
In the Linux kernel, the following vulnerability has been resolved: nommu: pass NULL argument to vma_iter_prealloc() When deleting a vma entry from a maple tree, it has to pass NULL to vma_iter_prealloc() in order to calculate internal state of the tree, but it passed a wrong argument. As a result, nommu kernels crashed upon accessing a vma iterator, such as acct_collect() reading the size of vma entries after do_munmap(). This commit fixes this issue by passing a right argument to the preallocation call.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.11.10-1 (forky)linux 6.11.10-1 (forky)
linuxlinux
linuxlinux>= b5df09226450165c434084d346fcb6d4858b0d52 < 8bbf0ab631cdf1dade6745f137cff98751e6ced78bbf0ab631cdf1dade6745f137cff98751e6ced7
linuxlinux>= b5df09226450165c434084d346fcb6d4858b0d52 < aceaf33b7666b72dfb86e0aa977be81e3bcbc727aceaf33b7666b72dfb86e0aa977be81e3bcbc727
linuxlinux>= b5df09226450165c434084d346fcb6d4858b0d52 < 247d720b2c5d22f7281437fd6054a138256986ba247d720b2c5d22f7281437fd6054a138256986ba
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.11.10-16.11.10-1
linuxlinux_kernel>= 0 < 6.11.10-16.11.10-1
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.6 < 6.6.636.6.63
linuxlinux_kernel>= 6.7 < 6.11.106.11.10
msrcazl3_kernel_6.6.57.1-7_on_azure_linux_3.0
msrcazl3_kernel_6.6.64.2-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.