CVE-2024-49936

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-49936
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-49936.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-49936
Downstream
Related
Published
2024-10-21T18:15:15Z
Modified
2025-08-09T20:01:26Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

net/xen-netback: prevent UAF in xenvifflushhash()

During the listforeachentryrcu iteration call of xenvifflushhash, kfreercu does not exist inside the rcu read critical section, so if kfreercu is called when the rcu grace period ends during the iteration, UAF occurs when accessing head->next after the entry becomes free.

Therefore, to solve this, you need to change it to listforeachentrysafe.

References

Affected packages