CVE-2024-47750

Source
https://cve.org/CVERecord?id=CVE-2024-47750
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-47750.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-47750
Downstream
Related
Published
2024-10-21T12:14:15Z
Modified
2026-08-12T03:30:36Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
RDMA/hns: Fix Use-After-Free of rsv_qp on HIP08
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/hns: Fix Use-After-Free of rsv_qp on HIP08

Currently rsv_qp is freed before ib_unregister_device() is called on HIP08. During the time interval, users can still dereg MR and rsv_qp will be used in this process, leading to a UAF. Move the release of rsv_qp after calling ib_unregister_device() to fix it.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47750.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
70f92521584f1d1e8268311ee84413307b0fdea8
Fixed
2ccf1c75d39949d8ea043d04a2e92d7100ea723d
Fixed
d2d9c5127122745da6e887f451dd248cfeffca33
Fixed
dac2723d8bfa9cf5333f477741e6e5fa1ed34645
Fixed
60595923371c2ebe7faf82536c47eb0c967e3425
Fixed
fd8489294dd2beefb70f12ec4f6132aeec61a4d0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-47750.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
6.1.113
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.54
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.10.13
Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.11.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-47750.json"