cbcvebase.
CVE-2024-53173
published 2024-12-27

CVE-2024-53173: In the Linux kernel, the following vulnerability has been resolved: NFSv4.0: Fix a use-after-free problem in the asynchronous open() Yang Erkun reports that…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.7th percentile
In the Linux kernel, the following vulnerability has been resolved: NFSv4.0: Fix a use-after-free problem in the asynchronous open() Yang Erkun reports that when two threads are opening files at the same time, and are forced to abort before a reply is seen, then the call to nfs_release_seqid() in nfs4_opendata_free() can result in a use-after-free of the pointer to the defunct rpc task of the other thread. The fix is to ensure that if the RPC call is aborted before the call to nfs_wait_on_sequence() is complete, then we must call nfs_release_seqid() in nfs4_open_release() before the rpc_task is freed.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 24ac23ab88df5b21b5b2df8cde748bf99b289099 < 1cfae9575296f5040cdc84b0730e79078c081d2d1cfae9575296f5040cdc84b0730e79078c081d2d
linuxlinux>= 24ac23ab88df5b21b5b2df8cde748bf99b289099 < 7bf6bf130af8ee7d93a99c28a7512df3017ec7597bf6bf130af8ee7d93a99c28a7512df3017ec759
linuxlinux>= 24ac23ab88df5b21b5b2df8cde748bf99b289099 < 5237a297ffd374a1c4157a53543b7a69d7bbbc035237a297ffd374a1c4157a53543b7a69d7bbbc03
linuxlinux>= 24ac23ab88df5b21b5b2df8cde748bf99b289099 < 2ab9639f16b05d948066a6c4cf19a0fdc61046ff2ab9639f16b05d948066a6c4cf19a0fdc61046ff
linuxlinux>= 24ac23ab88df5b21b5b2df8cde748bf99b289099 < ba6e6c04f60fe52d91520ac4d749d372d4c74521ba6e6c04f60fe52d91520ac4d749d372d4c74521
linuxlinux>= 24ac23ab88df5b21b5b2df8cde748bf99b289099 < 229a30ed42bb87bcb044c5523fabd9e4f0e75648229a30ed42bb87bcb044c5523fabd9e4f0e75648
linuxlinux>= 24ac23ab88df5b21b5b2df8cde748bf99b289099 < e2277a1d9d5cd0d625a4fd7c04fce2b53e66df77e2277a1d9d5cd0d625a4fd7c04fce2b53e66df77
linuxlinux>= 24ac23ab88df5b21b5b2df8cde748bf99b289099 < b56ae8e715557b4fc227c9381d2e681ffafe7b15b56ae8e715557b4fc227c9381d2e681ffafe7b15
linuxlinux>= 24ac23ab88df5b21b5b2df8cde748bf99b289099 < 2fdb05dc0931250574f0cb0ebeb5ed8e20f4a8892fdb05dc0931250574f0cb0ebeb5ed8e20f4a889
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 0 < 4.4.0-268.3024.4.0-268.302
linuxlinux_kernel>= 0 < 4.15.0-237.2494.15.0-237.249
linuxlinux_kernel>= 2.6.16 < 4.19.3254.19.325
linuxlinux_kernel>= 4.20 < 5.4.2875.4.287
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.