PT-2024-35561 · Linux+3 · Linux Kernel+3

Nirmoy Das

·

Published

2024-10-24

·

Updated

2026-05-26

·

CVE-2024-53098

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved. The issue is related to the drm/xe/ufence component, where the access ok() function only checks for address overflow, but not for invalid addresses sent from userspace. To catch such invalid addresses, the code now prefetches the ufence address and attempts to read it. This change aims to prevent exploitation of bogus addresses.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2025-12647
BDU:2025-07246
CVE-2024-53098
USN-7276-1
USN-7277-1
USN-7310-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Ubuntu