PT-2024-35594 · Linux+6 · Linux Kernel+6

Qun-Wei Lin

·

Published

2024-11-15

·

Updated

2026-03-14

·

CVE-2024-53128

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.11.9
Description The issue is related to the object is on stack() function in the Linux kernel, which may produce incorrect results when CONFIG KASAN SW TAGS and CONFIG KASAN STACK are enabled. This discrepancy can lead to incorrect stack object detection and trigger warnings if CONFIG DEBUG OBJECTS is also enabled. The problem arises due to the presence of tags in the obj pointer, while the stack pointer does not have tags.
Recommendations To resolve the issue, upgrade the Linux kernel to a version newer than 6.11.9. For Linux kernel versions prior to 6.11.9, consider disabling CONFIG KASAN SW TAGS and CONFIG KASAN STACK as a temporary workaround until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17211
ALT-PU-2025-12647
AZL-54272
AZL-54277
BDU:2025-12018
CVE-2024-53128
DLA-4076-1
DSA-5860-1
OESA-2025-1078
OESA-2025-1079
USN-7276-1
USN-7277-1
USN-7310-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1
USN-7654-1
USN-7654-2
USN-7654-3
USN-7654-4
USN-7654-5
USN-7655-1
USN-7686-1
USN-7711-1
USN-7712-1
USN-7712-2

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu