CVE-2024-53187

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Dec 27, 2024
Updated: Jan 16, 2025
CWE ID 190

Summary

CVE-2024-53187 is a vulnerability affecting the Linux kernel's io_uring component. Specifically, the function io_pin_pages contains a flaw where the uaddr parameter, which comes directly from the user, can lead to overflows if the size is not carefully checked. This issue can potentially result in memory corruption and other security risks. The vulnerability was identified during testing with syz-executor825 and was found in version 6.12.0-next-20241118-syzkaller. The Linux community released a patch to address this issue, and users are encouraged to update their kernels to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share