PT-2024-35594 · Linux+6 · Linux Kernel+6
Qun-Wei Lin
·
Published
2024-11-15
·
Updated
2026-03-14
·
CVE-2024-53128
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.11.9
Description
The issue is related to the
object is on stack() function in the Linux kernel, which may produce incorrect results when CONFIG KASAN SW TAGS and CONFIG KASAN STACK are enabled. This discrepancy can lead to incorrect stack object detection and trigger warnings if CONFIG DEBUG OBJECTS is also enabled. The problem arises due to the presence of tags in the obj pointer, while the stack pointer does not have tags.Recommendations
To resolve the issue, upgrade the Linux kernel to a version newer than 6.11.9.
For Linux kernel versions prior to 6.11.9, consider disabling
CONFIG KASAN SW TAGS and CONFIG KASAN STACK as a temporary workaround until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu