CVE-2024-50080

MEDIUM

Linux kernel - Privilege Escalation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ublk: don't allow user copy for unprivileged device UBLK_F_USER_COPY requires userspace to call write() on ublk char device for filling request buffer, and unprivileged device can't be trusted. So don't allow user copy for unprivileged device.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 10.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (12)
linux/Kernel 6.5.0 - 6.6.58linux
linux/Kernel 6.7.0 - 6.11.5linux
Linux/Linux < 6.5
Linux/Linux 1172d5b8beca6b899deb9f7f2850e7e47ec16198 - 42aafd8b48adac1c3b20fe5892b1b91b80c1a1e6
Linux/Linux 1172d5b8beca6b899deb9f7f2850e7e47ec16198 - 6414ab5c9c9c068eca6dc4fd3a036bc4b83164dc
Linux/Linux 1172d5b8beca6b899deb9f7f2850e7e47ec16198 - 8f3d5686a2409877c5e8e2540774d24ed2b4a4ce
Linux/Linux 6.11.5 - 6.11.*
Linux/Linux 6.12
Linux/Linux 6.5
Linux/Linux 6.6.58 - 6.6.*
... and 2 more
Published Oct 29, 2024
Tracked Since Feb 18, 2026