PT-2024-30750 · Linux+10 · Linux Kernel+10

Shakeel Butt

·

Published

2024-08-07

·

Updated

2025-09-29

·

CVE-2024-43892

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the protection of concurrent access to mem cgroup idr in the Linux kernel. The problem arises when idr remove() is called concurrently for different memcgs when they reach a reference count of zero. This can cause multiple memcgs to acquire the same ID, leading to crashes due to missing list lru one when other memcgs access the list lru. The kernel crashes were observed at a low frequency in the fleet, particularly in the list lru code, including list lru add(), list lru del(), and reparenting code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:8856
ALSA-2024:8870
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-11855
ALT-PU-2024-13979
ALT-PU-2024-14046
AZL-48662
BDU:2025-01924
CESA-2024_8856
CESA-2024_8870
CVE-2024-43892
DLA-3912-1
DLA-4008-1
DSA-5782-1
INFSA-2024_8856
INFSA-2024_8870
INFSA-2024_9315
MGASA-2024-0309
MGASA-2024-0310
OESA-2024-2255
OESA-2024-2256
OESA-2024-2257
OESA-2024-2258
OESA-2024-2296
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
RHSA-2024:8856
RHSA-2024:8870
RHSA-2024:9315
RHSA-2024_8856
RHSA-2024_8870
RHSA-2024_9315
RHSA-2025:3021
RLSA-2024:8856
RLSA-2024:8870
SUSE-SU-2024:3189-1
SUSE-SU-2024:3190-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3251-1
SUSE-SU-2024:3252-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:3483-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-7100-1
USN-7100-2
USN-7123-1
USN-7144-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7173-1
USN-7173-2
USN-7173-3
USN-7194-1
USN-7195-1
USN-7195-2
USN-7196-1
USN-7332-1
USN-7332-2
USN-7332-3
USN-7342-1
USN-7344-1
USN-7344-2
USN-7413-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu