cbcvebase.
CVE-2024-53206
published 2024-12-27

CVE-2024-53206: In the Linux kernel, the following vulnerability has been resolved: tcp: Fix use-after-free of nreq in reqsk_timer_handler(). The cited commit replaced…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.5th percentile
In the Linux kernel, the following vulnerability has been resolved: tcp: Fix use-after-free of nreq in reqsk_timer_handler(). The cited commit replaced inet_csk_reqsk_queue_drop_and_put() with __inet_csk_reqsk_queue_drop() and reqsk_put() in reqsk_timer_handler(). Then, oreq should be passed to reqsk_put() instead of req; otherwise use-after-free of nreq could happen when reqsk is migrated but the retry attempt failed (e.g. due to timeout). Let's pass oreq to reqsk_put().

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 5.10.237 < 5.115.11
linuxlinux>= 5.15.170 < 5.15.1745.15.174
linuxlinux>= 5.4.293 < 5.55.5
linuxlinux>= 5071beb59ee416e8ab456ac8647a4dabcda823b1 < 9a3c1ad93e6fba67b3a637cfa95a57a6685e49089a3c1ad93e6fba67b3a637cfa95a57a6685e4908
linuxlinux>= 51e34db64f4e43c7b055ccf881b7f3e0c31bb26d < d0eb14cb8c08b00c36a3d5dc57a6f428b301f721d0eb14cb8c08b00c36a3d5dc57a6f428b301f721
linuxlinux>= 6.1.115 < 6.1.1206.1.120
linuxlinux>= 6.11.6 < 6.11.116.11.11
linuxlinux>= 6.6.59 < 6.6.646.6.64
linuxlinux>= 8459d61fbf24967839a70235165673148c7c7f17 < 2dcc86fefe09ac853158afd96b60d544af115dc52dcc86fefe09ac853158afd96b60d544af115dc5
linuxlinux>= 997ae8da14f1639ce6fb66a063dab54031cd61b3 < 65ed89cad1f57034c256b016e89e8c0a4ec7c65b65ed89cad1f57034c256b016e89e8c0a4ec7c65b
linuxlinux>= e8c526f2bdf1845bedaf6a478816a3d06fa78b8f < 6d845028609a4af0ad66f499ee0bd5789122b0676d845028609a4af0ad66f499ee0bd5789122b067
linuxlinux>= e8c526f2bdf1845bedaf6a478816a3d06fa78b8f < c31e72d021db2714df03df6c42855a1db592716cc31e72d021db2714df03df6c42855a1db592716c
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 5.15.170 < 5.15.1745.15.174
linuxlinux_kernel>= 6.1.115 < 6.1.1206.1.120
linuxlinux_kernel>= 6.11.6 < 6.11.116.11.11
linuxlinux_kernel>= 6.12 < 6.12.26.12.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.