CVE-2024-41149

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-41149
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-41149.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-41149
Downstream
Related
Published
2025-01-11T12:35:33Z
Modified
2025-10-17T09:18:38.040794Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
block: avoid to reuse `hctx` not removed from cpuhp callback list
Details

In the Linux kernel, the following vulnerability has been resolved:

block: avoid to reuse hctx not removed from cpuhp callback list

If the 'hctx' isn't removed from cpuhp callback list, we can't reuse it, otherwise use-after-free may be triggered.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
58bf93580fec30d84a46be41171c5fad98b5cc70
Fixed
ee18012c80155f6809522804099621070c69ec72
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c1291ea131d186296dc8d328a36c3caf38e8e159
Fixed
b5792c162dcf6197bf3d2de2be6c8169435b73d0
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
22465bbac53c821319089016f268a2437de9b00a
Fixed
85672ca9ceeaa1dcf2777a7048af5f4aee3fd02b

Affected versions

v6.*

v6.12.6

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.12.6
Fixed
6.12.7