CVE-2024-38545
In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix UAF for cq async event The refcount of CQ is not protected by locks.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix UAF for cq async event The refcount of CQ is not protected by locks. When CQ asynchronous events and CQ destruction are concurrent, CQ may have been released, which will cause UAF. Use the xa_lock() to protect the CQ refcount.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/330c825e66ef65278e4ebe57fd49c1d6f3f4e34ePatch
- https://git.kernel.org/stable/c/37a7559dc1358a8d300437e99ed8ecdab0671507Patch
- https://git.kernel.org/stable/c/39d26cf46306bdc7ae809ecfdbfeff5aa1098911Patch
- https://git.kernel.org/stable/c/63da190eeb5c9d849b71f457b15b308c94cbaf08Patch
- https://git.kernel.org/stable/c/763780ef0336a973e933e40e919339381732dcafPatch
- https://git.kernel.org/stable/c/a942ec2745ca864cd8512142100e4027dc306a42Patch
- https://git.kernel.org/stable/c/37a7559dc1358a8d300437e99ed8ecdab0671507Patch
- https://git.kernel.org/stable/c/39d26cf46306bdc7ae809ecfdbfeff5aa1098911Patch
- https://git.kernel.org/stable/c/63da190eeb5c9d849b71f457b15b308c94cbaf08Patch
- https://git.kernel.org/stable/c/763780ef0336a973e933e40e919339381732dcafPatch
- https://git.kernel.org/stable/c/a942ec2745ca864cd8512142100e4027dc306a42Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.