PT-2024-35620 · Linux+8 · Linux Kernel+8

Yang Erkun

·

Published

2024-11-18

·

Updated

2025-11-07

·

CVE-2024-53174

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.12.0-rc3+
Description A vulnerability in the Linux kernel has been resolved, related to the SUNRPC module. The function c show was called with protection from RCU, which only ensures that cp will not be freed. However, the reference count for cp can drop to zero, triggering a refcount use-after-free warning when cache get is called. To resolve this issue, cache get rcu is used to ensure that cp remains active. This vulnerability can cause a use-after-free warning, as seen in the call trace.
Recommendations To resolve this issue, update to a version of the Linux kernel that includes the fix, which ensures that cp remains active by using cache get rcu. As a temporary workaround, consider disabling the c show function until a patch is available. Restrict access to the SUNRPC module to minimize the risk of exploitation. Avoid using the cache get function in the affected API endpoint until the issue is resolved.

Exploit

Fix

Use After Free

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12647
BDU:2025-04556
CVE-2024-53174
DLA-4075-1
DLA-4076-1
INFSA-2025_6966
OESA-2025-1372
OESA-2025-1450
OESA-2025-2632
OESA-2025-2636
OPENSUSE-SU-2025_0117-1
OPENSUSE-SU-2025_0153-1
OPENSUSE-SU-2025_0154-1
OPENSUSE-SU-2025_0556-1
OPENSUSE-SU-2025_0577-1
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2025:0117-1
SUSE-SU-2025:0153-1
SUSE-SU-2025:0154-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:0556-1
SUSE-SU-2025:0577-1
SUSE-SU-2025:0577-2
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0577-1
SUSE-SU-2025_0577-2
USN-7276-1
USN-7277-1
USN-7310-1
USN-7387-1
USN-7387-2
USN-7387-3
USN-7388-1
USN-7389-1
USN-7390-1
USN-7391-1
USN-7392-1
USN-7392-2
USN-7392-3
USN-7392-4
USN-7393-1
USN-7401-1
USN-7407-1
USN-7413-1
USN-7421-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7458-1
USN-7459-1
USN-7459-2
USN-7463-1
USN-7468-1
USN-7523-1
USN-7524-1
USN-7539-1
USN-7540-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu