cbcvebase.
CVE-2024-53165
published 2024-12-27

CVE-2024-53165: In the Linux kernel, the following vulnerability has been resolved: sh: intc: Fix use-after-free bug in register_intc_controller() In the error handling for…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.6th percentile
In the Linux kernel, the following vulnerability has been resolved: sh: intc: Fix use-after-free bug in register_intc_controller() In the error handling for this function, d is freed without ever removing it from intc_list which would lead to a use after free. To fix this, let's only add it to the list after everything has succeeded.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 2dcec7a988a1895540460a0bf5603bab63d5a3ed < 3c7c806b3eafd94ae0f77305a174d63b69ec187c3c7c806b3eafd94ae0f77305a174d63b69ec187c
linuxlinux>= 2dcec7a988a1895540460a0bf5603bab63d5a3ed < d8de818df12d86a1a26a8efd7b4b3b9c6dc3c5ccd8de818df12d86a1a26a8efd7b4b3b9c6dc3c5cc
linuxlinux>= 2dcec7a988a1895540460a0bf5603bab63d5a3ed < 971b4893457788e0e123ea552f0bb126a5300e61971b4893457788e0e123ea552f0bb126a5300e61
linuxlinux>= 2dcec7a988a1895540460a0bf5603bab63d5a3ed < c3f4f4547fb291982f5ef56c048277c4d5ccc4e4c3f4f4547fb291982f5ef56c048277c4d5ccc4e4
linuxlinux>= 2dcec7a988a1895540460a0bf5603bab63d5a3ed < c43df7dae28fb9fce96ef088250c1e3c3a77c527c43df7dae28fb9fce96ef088250c1e3c3a77c527
linuxlinux>= 2dcec7a988a1895540460a0bf5603bab63d5a3ed < b8b84dcdf3ab1d414304819f824b10efba64132cb8b84dcdf3ab1d414304819f824b10efba64132c
linuxlinux>= 2dcec7a988a1895540460a0bf5603bab63d5a3ed < 6ba6e19912570b2ad68298be0be1dc779014a3036ba6e19912570b2ad68298be0be1dc779014a303
linuxlinux>= 2dcec7a988a1895540460a0bf5603bab63d5a3ed < 588bdec1ff8b81517dbae0ae51c9df52c0b952d3588bdec1ff8b81517dbae0ae51c9df52c0b952d3
linuxlinux>= 2dcec7a988a1895540460a0bf5603bab63d5a3ed < 63e72e551942642c48456a4134975136cdcb9b3c63e72e551942642c48456a4134975136cdcb9b3c
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-56.586.8.0-56.58
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 0 < 4.4.0-267.3014.4.0-267.301
linuxlinux_kernel>= 0 < 4.15.0-236.2484.15.0-236.248
linuxlinux_kernel>= 2.6.30 < 4.19.3254.19.325
linuxlinux_kernel>= 4.20 < 5.4.2875.4.287
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.