PT-2024-10006 · Linux+5 · Linux Kernel+5

Mickaël Salaün

·

Published

2024-04-08

·

Updated

2025-09-29

·

CVE-2024-38561

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a race condition in the Linux kernel's kunit framework, specifically in the kunit try catch run() function. This condition occurs when a kthread finishes after the deadline and before the call to kthread stop(), which may lead to use after free. The vulnerability may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-13979
ALT-PU-2024-14046
BDU:2025-00133
CVE-2024-38561
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1961
OESA-2024-1962
OESA-2024-1964
OESA-2024-2076
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu