cbcvebase.
CVE-2024-56709
published 2024-12-29

CVE-2024-56709: In the Linux kernel, the following vulnerability has been resolved: io_uring: check if iowq is killed before queuing task work can be executed after the task…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.1th percentile
In the Linux kernel, the following vulnerability has been resolved: io_uring: check if iowq is killed before queuing task work can be executed after the task has gone through io_uring termination, whether it's the final task_work run or the fallback path. In this case, task work will find ->io_wq being already killed and null'ed, which is a problem if it then tries to forward the request to io_queue_iowq(). Make io_queue_iowq() fail requests in this case. Note that it also checks PF_KTHREAD, because the user can first close a DEFER_TASKRUN ring and shortly after kill the task, in which case ->iowq check would race.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 773af69121ecc6c53d192661af8d53bb3db028ae < 534d59ab38010aada88390db65985e65d0de7d9e534d59ab38010aada88390db65985e65d0de7d9e
linuxlinux>= 773af69121ecc6c53d192661af8d53bb3db028ae < 2ca94c8de36091067b9ce7527ae8db3812d387812ca94c8de36091067b9ce7527ae8db3812d38781
linuxlinux>= 773af69121ecc6c53d192661af8d53bb3db028ae < 4f95a2186b7f2af09331e1e8069bcaf34fe019cf4f95a2186b7f2af09331e1e8069bcaf34fe019cf
linuxlinux>= 773af69121ecc6c53d192661af8d53bb3db028ae < dbd2ca9367eb19bc5e269b8c58b0b1514ada9156dbd2ca9367eb19bc5e269b8c58b0b1514ada9156
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 5.14.1 < 6.1.1226.1.122
linuxlinux_kernel>= 6.2 < 6.6.686.6.68
linuxlinux_kernel>= 6.7 < 6.12.76.12.7
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc6.1MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.