PT-2024-35616 · Linux+9 · Linux Kernel+9

Yu Kuai

·

Published

2024-11-18

·

Updated

2025-11-12

·

CVE-2024-53170

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6
Description A use-after-free vulnerability has been identified in the Linux kernel, specifically in the block layer. The issue arises when the blk mq clear flush rq mapping() function is not called during the SCSI probe, leading to a situation where the QUEUE FLAG INIT DONE flag is cleared, causing a use-after-free error in the blk mq find and get req() function. This vulnerability can be exploited by an attacker to potentially gain elevated privileges or cause a denial-of-service condition.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, for Linux kernel version 6.6, ensure that the patch for this issue is applied. If the patch is not available, consider disabling the affected functionality or restricting access to the vulnerable component as a temporary workaround.
Note: The provided information does not include specific guidance on how to apply the patch or update the kernel. It is recommended to follow the standard procedure for updating the Linux kernel on your system.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:20518
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALSA-2025_18281
ALSA-2025_19102
ALSA-2025_19103
ALSA-2025_19409
ALSA-2025_20518
ALT-PU-2025-12647
AZL-55715
BDU:2025-04995
CVE-2024-53170
DLA-4076-1
DSA-5860-1
INFSA-2025_20518
OESA-2025-1032
OESA-2025-1036
OPENSUSE-SU-2025_0428-1
OPENSUSE-SU-2025_0499-1
OPENSUSE-SU-2025_0557-1
RHSA-2025:20518
RHSA-2025_20518
SUSE-SU-2025:0289-1
SUSE-SU-2025:0428-1
SUSE-SU-2025:0499-1
SUSE-SU-2025:0557-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0428-1
SUSE-SU-2025_0499-1
SUSE-SU-2025_0557-1
USN-7276-1
USN-7277-1
USN-7310-1
USN-7383-1
USN-7383-2
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7403-1
USN-7451-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu