CVE-2024-41149

HIGH

Linux Kernel - Use-After-Free in Block Layer CPU Hotplug Callback

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: block: avoid to reuse `hctx` not removed from cpuhp callback list If the 'hctx' isn't removed from cpuhp callback list, we can't reuse it, otherwise use-after-free may be triggered.

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 12.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (7)
linux/Kernel 6.12.6 - 6.12.7linux
Linux/Linux 22465bbac53c821319089016f268a2437de9b00a - 85672ca9ceeaa1dcf2777a7048af5f4aee3fd02b
Linux/Linux 58bf93580fec30d84a46be41171c5fad98b5cc70 - ee18012c80155f6809522804099621070c69ec72
Linux/Linux 6.12.6 - 6.12.7
Linux/Linux c1291ea131d186296dc8d328a36c3caf38e8e159 - b5792c162dcf6197bf3d2de2be6c8169435b73d0
linux/linux_kernel 6.12.6
linux/linux_kernel 6.13 rc2 (2 CPE variants)
Published Jan 11, 2025
Tracked Since Feb 18, 2026