Use-after-free in Linux kernel sched



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2024-53057
CWE-ID CWE-416
Exploitation vector Local
Public exploit N/A
Vulnerable software
Linux kernel
Operating systems & Components / Operating system

Vendor Linux Foundation

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Use-after-free

EUVDB-ID: #VU100707

Risk: Low

CVSSv3.1: 7.7 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-53057

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the qdisc_tree_reduce_backlog() function in net/sched/sch_api.c. A local user can escalate privileges on the system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions

CPE2.3 External links

http://git.kernel.org/stable/c/e7f9a6f97eb067599a74f3bcb6761976b0ed303e
http://git.kernel.org/stable/c/dbe778b08b5101df9e89bc06e0a3a7ecd2f4ef20
http://git.kernel.org/stable/c/ce691c814bc7a3c30c220ffb5b7422715458fd9b
http://git.kernel.org/stable/c/05df1b1dff8f197f1c275b57ccb2ca33021df552
http://git.kernel.org/stable/c/580b3189c1972aff0f993837567d36392e9d981b
http://git.kernel.org/stable/c/597cf9748c3477bf61bc35f0634129f56764ad24
http://git.kernel.org/stable/c/9995909615c3431a5304c1210face5f268d24dba
http://git.kernel.org/stable/c/2e95c4384438adeaa772caa560244b1a2efef816


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###