cbcvebase.
CVE-2024-53119
published 2024-12-02

CVE-2024-53119: In the Linux kernel, the following vulnerability has been resolved: virtio/vsock: Fix accept_queue memory leak As the final stages of socket destruction may be…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.4th percentile
In the Linux kernel, the following vulnerability has been resolved: virtio/vsock: Fix accept_queue memory leak As the final stages of socket destruction may be delayed, it is possible that virtio_transport_recv_listen() will be called after the accept_queue has been flushed, but before the SOCK_DONE flag has been set. As a result, sockets enqueued after the flush would remain unremoved, leading to a memory leak. vsock_release __vsock_release lock virtio_transport_release virtio_transport_close schedule_delayed_work(close_work) sk_shutdown = SHUTDOWN_MASK (!) flush accept_queue release virtio_transport_recv_pkt vsock_find_bound_socket lock if flag(SOCK_DONE) return virtio_transport_recv_listen child = vsock_create_connected (!) vsock_enqueue_accept(child) release close_work lock virtio_transport_do_close set_flag(SOCK_DONE) virtio_transport_remove_sock vsock_remove_sock vsock_remove_bound release Introduce a sk_shutdown check to disallow vsock_enqueue_accept() during socket destruction. unreferenced object 0xffff888109e3f800 (size 2040): comm "kworker/5:2", pid 371, jiffies 4294940105 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 28 00 0b 40 00 00 00 00 00 00 00 00 00 00 00 00 (..@............ backtrace (crc 9e5f4e84): [] kmem_cache_alloc_noprof+0x2c1/0x360 [] sk_prot_alloc+0x30/0x120 [] sk_alloc+0x2c/0x4b0 [] __vsock_create.constprop.0+0x2a/0x310 [] virtio_transport_recv_pkt+0x4dc/0x9a0 [] vsock_loopback_work+0xfd/0x140 [] process_one_work+0x20c/0x570 [] worker_thread+0x1bf/0x3a0 [] kthread+0xdd/0x110 [] ret_from_fork+0x2d/0x50 [] ret_from_fork_asm+0x1a/0x30

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 3fe356d58efae54dade9ec94ea7c919ed20cf4db < e26fa236758e8baa61a82cfd9fd4388d2e8d6a4ce26fa236758e8baa61a82cfd9fd4388d2e8d6a4c
linuxlinux>= 3fe356d58efae54dade9ec94ea7c919ed20cf4db < 4310902c766e371359e6c6311056ae80b5beeac94310902c766e371359e6c6311056ae80b5beeac9
linuxlinux>= 3fe356d58efae54dade9ec94ea7c919ed20cf4db < 946c7600fa2207cc8d3fbc86a518ec56f98a5813946c7600fa2207cc8d3fbc86a518ec56f98a5813
linuxlinux>= 3fe356d58efae54dade9ec94ea7c919ed20cf4db < 897617a413e0bf1c6380e3b34b2f28f450508549897617a413e0bf1c6380e3b34b2f28f450508549
linuxlinux>= 3fe356d58efae54dade9ec94ea7c919ed20cf4db < 2415345042245de7601dcc6eafdbe3a3dcc9e3792415345042245de7601dcc6eafdbe3a3dcc9e379
linuxlinux>= 3fe356d58efae54dade9ec94ea7c919ed20cf4db < d7b0ff5a866724c3ad21f2628c22a63336deec3fd7b0ff5a866724c3ad21f2628c22a63336deec3f
linuxlinux>= 5.9.13 < 5.105.10
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.10-16.11.10-1
linuxlinux_kernel>= 0 < 6.11.10-16.11.10-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.10 < 6.1.1196.1.119
linuxlinux_kernel>= 6.2 < 6.6.636.6.63
linuxlinux_kernel>= 6.7 < 6.11.106.11.10
msrcazl3_kernel_6.6.57.1-7_on_azure_linux_3.0
msrcazl3_kernel_6.6.64.2-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.176.3-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.