CVE-2024-50119

MEDIUM

Linux Kernel 6.10-6.11.5 - Use-After-Free in CIFS IO Request Pool Destruction

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: cifs: fix warning when destroy 'cifs_io_request_pool' There's a issue as follows: WARNING: CPU: 1 PID: 27826 at mm/slub.c:4698 free_large_kmalloc+0xac/0xe0 RIP: 0010:free_large_kmalloc+0xac/0xe0 Call Trace: <TASK> ? __warn+0xea/0x330 mempool_destroy+0x13f/0x1d0 init_cifs+0xa50/0xff0 [cifs] do_one_initcall+0xdc/0x550 do_init_module+0x22d/0x6b0 load_module+0x4e96/0x5ff0 init_module_from_file+0xcd/0x130 idempotent_init_module+0x330/0x620 __x64_sys_finit_module+0xb3/0x110 do_syscall_64+0xc1/0x1d0 entry_SYSCALL_64_after_hwframe+0x77/0x7f Obviously, 'cifs_io_request_pool' is not created by mempool_create(). So just use mempool_exit() to revert 'cifs_io_request_pool'.

Scores

CVSS v3 5.5
EPSS 0.0019
EPSS Percentile 8.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (9)
linux/Kernel 6.10.0 - 6.11.6linux
Linux/Linux < 6.10
Linux/Linux 6.10
Linux/Linux 6.11.6 - 6.11.*
Linux/Linux 6.12
Linux/Linux edea94a69730b74a8867bbafe742c3fc4e580722 - 2ce1007f42b8a6a0814386cb056feb28dc6d6091
Linux/Linux edea94a69730b74a8867bbafe742c3fc4e580722 - 726416a253c51037636ecc65ad3dada3d02dcaea
linux/linux_kernel 6.12 rc1 (4 CPE variants)
linux/linux_kernel 6.10 - 6.11.6
Published Nov 05, 2024
Tracked Since Feb 18, 2026