CVE-2024-2193

MEDIUM

CPU <Speculative Execution - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-2193. PoCs published by uthrasri.

AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2024-2193, targeting a vulnerability in the Linux kernel's autogroup scheduling feature. The code includes modifications to kernel scheduling components, particularly in autogroup.c, which manipulates task group handling to exploit the vulnerability.

Description

A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.

Exploits (1)

nomisec WORKING POC
by uthrasri · poc
https://github.com/uthrasri/CVE-2024-2193

This repository contains a functional exploit PoC for CVE-2024-2193, targeting a vulnerability in the Linux kernel's autogroup scheduling feature. The code includes modifications to kernel scheduling components, particularly in autogroup.c, which manipulates task group handling to exploit the vulnerability.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Linux Kernel (specific version not specified)
No auth needed
Prerequisites: Access to a vulnerable Linux kernel · Ability to compile and load kernel modules
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 5.7
EPSS 0.0123
EPSS Percentile 65.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-362
Status published
Products (2)
AMD/CPU See advisory AMD-SB-7016
Xen/Xen consult Xen advisory XSA-453
Published Mar 15, 2024
Tracked Since Feb 18, 2026