CVE-2024-53170
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-53170 is a Linux kernel vulnerability affecting the block subsystem. The issue lies in the blk_mq_find_and_get_req function, which fails to call blk_mq_clear_flush_rq_mapping under certain conditions. As a result, a use-after-free (UAF) vulnerability is introduced, leading to kernel memory corruption. This vulnerability was discovered by the KASAN memory error detector and was triggered during the scsi probe process. The affected kernel versions are prior to 6.6.0-ga836a5060850. The UAF can lead to a denial-of-service (DoS) attack or potentially allow an attacker to gain privileged access to the system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX