cbcvebase.
CVE-2024-53181
published 2024-12-27

CVE-2024-53181: In the Linux kernel, the following vulnerability has been resolved: um: vector: Do not use drvdata in release The drvdata is not available in release. Let's…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.1th percentile
In the Linux kernel, the following vulnerability has been resolved: um: vector: Do not use drvdata in release The drvdata is not available in release. Let's just use container_of() to get the vector_device instance. Otherwise, removing a vector device will result in a crash: RIP: 0033:vector_device_release+0xf/0x50 RSP: 00000000e187bc40 EFLAGS: 00010202 RAX: 0000000060028f61 RBX: 00000000600f1baf RCX: 00000000620074e0 RDX: 000000006220b9c0 RSI: 0000000060551c80 RDI: 0000000000000000 RBP: 00000000e187bc50 R08: 00000000603ad594 R09: 00000000e187bb70 R10: 000000000000135a R11: 00000000603ad422 R12: 00000000623ae028 R13: 000000006287a200 R14: 0000000062006d30 R15: 00000000623700b6 Kernel panic - not syncing: Segfault with no mm CPU: 0 UID: 0 PID: 16 Comm: kworker/0:1 Not tainted 6.12.0-rc6-g59b723cd2adb #1 Workqueue: events mc_work_proc Stack: 60028f61 623ae028 e187bc80 60276fcd 6220b9c0 603f5820 623ae028 00000000 e187bcb0 603a2bcd 623ae000 62370010 Call Trace: [] ? vector_device_release+0x0/0x50 [] device_release+0x70/0xba [] kobject_put+0xba/0xe7 [] put_device+0x19/0x1c [] platform_device_put+0x26/0x29 [] platform_device_unregister+0x2c/0x2e [] vector_remove+0x52/0x58 [] ? mconsole_reply+0x0/0x50 [] mconsole_remove+0x160/0x1cc [] ? strlen+0x0/0x15 [] ? __dequeue_entity+0x1a9/0x206 [] ? set_next_entity+0x39/0x63 [] ? set_next_entity+0x0/0x63 [] ? um_set_signals+0x0/0x43 [] mc_work_proc+0x77/0x91 [] process_scheduled_works+0x1b3/0x2dd [] ? assign_work+0x0/0x58 [] worker_thread+0x1e9/0x293 [] ? set_pf_worker+0x0/0x64 [] ? arch_local_irq_save+0x0/0x2d [] ? kthread_exit+0x0/0x3a [] ? worker_thread+0x0/0x293 [] kthread+0x126/0x12b [] new_thread_handler+0x85/0xb6

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < 8ed7793f6f589b4e1f0b38f8448578d2a48f9c828ed7793f6f589b4e1f0b38f8448578d2a48f9c82
linuxlinux>= 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < 376c7f0beb8f6f3800fc3013ef2f422d0cbfbf92376c7f0beb8f6f3800fc3013ef2f422d0cbfbf92
linuxlinux>= 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < 35f8f72b45791a6a71b81140c59d02a6183b6f3b35f8f72b45791a6a71b81140c59d02a6183b6f3b
linuxlinux>= 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < bef9a2835011668c221851a7572b6c8433087f85bef9a2835011668c221851a7572b6c8433087f85
linuxlinux>= 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < dc5251b1af5c9a0749322bf58bd5aa673f545fe2dc5251b1af5c9a0749322bf58bd5aa673f545fe2
linuxlinux>= 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < 8204dd589c4f25a7618eece5da3f0871e02af8ae8204dd589c4f25a7618eece5da3f0871e02af8ae
linuxlinux>= 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < e9d36f7e71a907ec507f84ee5d60a622c345cac4e9d36f7e71a907ec507f84ee5d60a622c345cac4
linuxlinux>= 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < 12f52e373d63f008ee386f371bdd82a3a377919912f52e373d63f008ee386f371bdd82a3a3779199
linuxlinux>= 49da7e64f33e80edffb1a9eeb230fa4c3f42dffb < 51b39d741970742a5c41136241a9c48ac607cf8251b39d741970742a5c41136241a9c48ac607cf82
linuxlinux_kernel< 4.19.3254.19.325
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.20 < 5.4.2875.4.287
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.