CVE-2024-53224

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Dec 27, 2024
Updated: Feb 3, 2025
CWE ID 476

Summary

[CVE-2024-53224]: The Linux kernel has addressed a vulnerability in the RDMA/mlx5 subsystem. The issue involved a race condition between device deregistration and pkey change work, leading to a NULL pointer dereference and subsequent kernel panic. This vulnerability has been resolved by moving pkey change work initialization and cleanup from device resources to the notifier stage, ensuring notifiers are deregistered before devices during cleanup. The vulnerability could result in a denial-of-service or arbitrary code execution, making it critical to apply the Linux kernel update.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share