CVE-2024-53182
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-53182 is a vulnerability in the Linux kernel that affects the bic (Bandwidth Control Instruction) subsystem of the bfq (Budget Fair Queuing) I/O scheduler. This issue is caused by a reverted commit that resulted in an use-after-free condition in the bic_set_bfqq function. The vulnerability was identified by the KASAN memory error detector and can lead to a kernel crash and potential code execution. The issue was first reported in a kernel crash log with a stack trace, which showed the affected function calls. The vulnerability was addressed by reverting the problematic commit.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX