cbcvebase.
CVE-2024-57979
published 2025-02-27

CVE-2024-57979: In the Linux kernel, the following vulnerability has been resolved: pps: Fix a use-after-free On a board running ntpd and gpsd, I'm seeing a consistent…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.2th percentile
In the Linux kernel, the following vulnerability has been resolved: pps: Fix a use-after-free On a board running ntpd and gpsd, I'm seeing a consistent use-after-free in sys_exit() from gpsd when rebooting: pps pps1: removed ------------[ cut here ]------------ kobject: '(null)' (00000000db4bec24): is not initialized, yet kobject_put() is being called. WARNING: CPU: 2 PID: 440 at lib/kobject.c:734 kobject_put+0x120/0x150 CPU: 2 UID: 299 PID: 440 Comm: gpsd Not tainted 6.11.0-rc6-00308-gb31c44928842 #1 Hardware name: Raspberry Pi 4 Model B Rev 1.1 (DT) pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : kobject_put+0x120/0x150 lr : kobject_put+0x120/0x150 sp : ffffffc0803d3ae0 x29: ffffffc0803d3ae0 x28: ffffff8042dc9738 x27: 0000000000000001 x26: 0000000000000000 x25: ffffff8042dc9040 x24: ffffff8042dc9440 x23: ffffff80402a4620 x22: ffffff8042ef4bd0 x21: ffffff80405cb600 x20: 000000000008001b x19: ffffff8040b3b6e0 x18: 0000000000000000 x17: 0000000000000000 x16: 0000000000000000 x15: 696e6920746f6e20 x14: 7369203a29343263 x13: 205d303434542020 x12: 0000000000000000 x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000 x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000 x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000 x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000 Call trace: kobject_put+0x120/0x150 cdev_put+0x20/0x3c __fput+0x2c4/0x2d8 ____fput+0x1c/0x38 task_work_run+0x70/0xfc do_exit+0x2a0/0x924 do_group_exit+0x34/0x90 get_signal+0x7fc/0x8c0 do_signal+0x128/0x13b4 do_notify_resume+0xdc/0x160 el0_svc+0xd4/0xf8 el0t_64_sync_handler+0x140/0x14c el0t_64_sync+0x190/0x194 ---[ end trace 0000000000000000 ]--- ...followed by more symptoms of corruption, with similar stacks: refcount_t: underflow; use-after-free. kernel BUG at lib/list_debug.c:62! Kernel panic - not syncing: Oops - BUG: Fatal exception This happens because pps_device_destruct() frees the pps_device with the embedded cdev im

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.2.40 < 3.33.3
linuxlinux>= 3.4.87 < 3.53.5
linuxlinux>= 3.8.1 < 3.93.9
linuxlinux>= d953e0e837e65ecc1ddaa4f9560f7925878a0de6 < 785c78ed0d39d1717cca3ef931d3e51337b5e90e785c78ed0d39d1717cca3ef931d3e51337b5e90e
linuxlinux>= d953e0e837e65ecc1ddaa4f9560f7925878a0de6 < 1a7735ab2cb9747518a7416fb5929e85442dec621a7735ab2cb9747518a7416fb5929e85442dec62
linuxlinux>= d953e0e837e65ecc1ddaa4f9560f7925878a0de6 < c4041b6b0a7a3def8cf3f3d6120ff337bc4c40f7c4041b6b0a7a3def8cf3f3d6120ff337bc4c40f7
linuxlinux>= d953e0e837e65ecc1ddaa4f9560f7925878a0de6 < 91932db1d96b2952299ce30c1c693d834d10ace691932db1d96b2952299ce30c1c693d834d10ace6
linuxlinux>= d953e0e837e65ecc1ddaa4f9560f7925878a0de6 < cd3bbcb6b3a7caa5ce67de76723b6d8531fb7f64cd3bbcb6b3a7caa5ce67de76723b6d8531fb7f64
linuxlinux>= d953e0e837e65ecc1ddaa4f9560f7925878a0de6 < 7e5ee3281dc09014367f5112b6d566ba36ea2d497e5ee3281dc09014367f5112b6d566ba36ea2d49
linuxlinux>= d953e0e837e65ecc1ddaa4f9560f7925878a0de6 < 85241f7de216f8298f6e48540ea13d7dcd10087085241f7de216f8298f6e48540ea13d7dcd100870
linuxlinux>= d953e0e837e65ecc1ddaa4f9560f7925878a0de6 < c79a39dc8d060b9e64e8b0fa9d245d44befeefbec79a39dc8d060b9e64e8b0fa9d245d44befeefbe
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 3.2.40 < 3.33.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.