PT-2024-35555 · Linux+7 · Linux Kernel+7

Zijian Zhang

·

Published

2024-11-06

·

Updated

2026-05-26

·

CVE-2024-53091

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.65
Description A vulnerability in the Linux kernel has been resolved. The issue is related to the introduction of support for vsock and unix sockets in sockmap, where the function tls sw has ctx tx/rx cannot presume the socket passed in must be IS ICSK. This can cause tls get ctx to return an invalid pointer and result in a page fault in the function tls sw ctx rx. The error is characterized by an inability to handle a page fault for a specific address. Technical details include the involvement of sk psock strp data ready and virtio transport recv pkt functions.
Recommendations To resolve the issue, update to Linux kernel version 6.6.65 or later. As a temporary workaround, consider restricting the use of the vulnerable tls sw has ctx tx/rx function until a patch is available. Additionally, be cautious when using vsock and af unix sockets, as they may be affected by this issue.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17891
ALT-PU-2025-12647
AZL-54616
AZL-54629
BDU:2025-15056
CVE-2024-53091
ECHO-31D7-EFBD-8602
INFSA-2025_6966
MGASA-2024-0392
MGASA-2024-0393
OESA-2025-1097
OPENSUSE-SU-2025_0428-1
OPENSUSE-SU-2025_0499-1
OPENSUSE-SU-2025_0557-1
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2025:0289-1
SUSE-SU-2025:0428-1
SUSE-SU-2025:0499-1
SUSE-SU-2025:0557-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0428-1
SUSE-SU-2025_0499-1
SUSE-SU-2025_0557-1
USN-7276-1
USN-7277-1
USN-7310-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu