cbcvebase.
CVE-2024-53184
published 2024-12-27

CVE-2024-53184: In the Linux kernel, the following vulnerability has been resolved: um: ubd: Do not use drvdata in release The drvdata is not available in release. Let's just…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.0th percentile
In the Linux kernel, the following vulnerability has been resolved: um: ubd: Do not use drvdata in release The drvdata is not available in release. Let's just use container_of() to get the ubd instance. Otherwise, removing a ubd device will result in a crash: RIP: 0033:blk_mq_free_tag_set+0x1f/0xba RSP: 00000000e2083bf0 EFLAGS: 00010246 RAX: 000000006021463a RBX: 0000000000000348 RCX: 0000000062604d00 RDX: 0000000004208060 RSI: 00000000605241a0 RDI: 0000000000000348 RBP: 00000000e2083c10 R08: 0000000062414010 R09: 00000000601603f7 R10: 000000000000133a R11: 000000006038c4bd R12: 0000000000000000 R13: 0000000060213a5c R14: 0000000062405d20 R15: 00000000604f7aa0 Kernel panic - not syncing: Segfault with no mm CPU: 0 PID: 17 Comm: kworker/0:1 Not tainted 6.8.0-rc3-00107-gba3f67c11638 #1 Workqueue: events mc_work_proc Stack: 00000000 604f7ef0 62c5d000 62405d20 e2083c30 6002c776 6002c755 600e47ff e2083c60 6025ffe3 04208060 603d36e0 Call Trace: [] ubd_device_release+0x21/0x55 [] ? ubd_device_release+0x0/0x55 [] ? kfree+0x0/0x100 [] device_release+0x70/0xba [] kobject_put+0xb5/0xe2 [] put_device+0x19/0x1c [] platform_device_put+0x26/0x29 [] platform_device_unregister+0x2c/0x2e [] ubd_remove+0xb8/0xd6 [] ? mconsole_reply+0x0/0x50 [] mconsole_remove+0x160/0x1cc [] ? mconsole_reply+0x48/0x50 [] ? um_set_signals+0x3b/0x43 [] ? update_min_vruntime+0x14/0x70 [] ? dequeue_task_fair+0x164/0x235 [] ? update_cfs_group+0x0/0x40 [] ? __schedule+0x0/0x3ed [] ? um_set_signals+0x0/0x43 [] mc_work_proc+0x77/0x91 [] process_scheduled_works+0x1af/0x2c3 [] ? assign_work+0x0/0x58 [] worker_thread+0x2f7/0x37a [] ? set_pf_worker+0x0/0x64 [] ? arch_local_irq_save+0x0/0x2d [] ? kthread_exit+0x0/0x3a [] ? worker_thread+0x0/0x37a [] kthread+0x130/0x135 [] new_thread_handler+0x85/0xb6

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 0998d0631001288a5974afc0b2a5f568bcdecb4d < 23d742a3fcd4781eed015a3a93e6a0e3ab1ef2a823d742a3fcd4781eed015a3a93e6a0e3ab1ef2a8
linuxlinux>= 0998d0631001288a5974afc0b2a5f568bcdecb4d < 300e277e463e6326938dd55ea560eafa0f5c88a5300e277e463e6326938dd55ea560eafa0f5c88a5
linuxlinux>= 0998d0631001288a5974afc0b2a5f568bcdecb4d < 509ba8746f812e45a05034ba18b73db574693d11509ba8746f812e45a05034ba18b73db574693d11
linuxlinux>= 0998d0631001288a5974afc0b2a5f568bcdecb4d < 5727343348f34e11a7c5a2a944d5aa505731d8765727343348f34e11a7c5a2a944d5aa505731d876
linuxlinux>= 0998d0631001288a5974afc0b2a5f568bcdecb4d < a5a75207efae4b558aaa34c288de7d6f2e926b4ba5a75207efae4b558aaa34c288de7d6f2e926b4b
linuxlinux>= 0998d0631001288a5974afc0b2a5f568bcdecb4d < 2d194d951895df214e066d08146e77cb6e02c1d42d194d951895df214e066d08146e77cb6e02c1d4
linuxlinux>= 0998d0631001288a5974afc0b2a5f568bcdecb4d < e6e5a4cded9bef3a1b0a4fac815b7176eb9a18ece6e5a4cded9bef3a1b0a4fac815b7176eb9a18ec
linuxlinux>= 0998d0631001288a5974afc0b2a5f568bcdecb4d < 16cf8511680809a9f20b3dd224c06d482648f9e216cf8511680809a9f20b3dd224c06d482648f9e2
linuxlinux>= 0998d0631001288a5974afc0b2a5f568bcdecb4d < 5bee35e5389f450a7eea7318deb9073e9414d3b15bee35e5389f450a7eea7318deb9073e9414d3b1
linuxlinux_kernel< 4.19.3254.19.325
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.20 < 5.4.2875.4.287
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.