PT-2024-35634 · Linux+5 · Linux Kernel+5

Published

2024-11-26

·

Updated

2026-05-26

·

CVE-2024-53187

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.12.0-next-20241118-syzkaller
Description The issue is related to the io uring feature in the Linux kernel, where the io pin pages function does not properly check for overflows. The uaddr parameter of io pin pages() comes directly from the user and can contain garbage data, which can lead to overflows if size is simply added to it. This can cause problems in the io uaddr map function and other related functions like io rings map and io allocate scq urings.
Recommendations For Linux kernel versions prior to 6.12.0-next-20241118-syzkaller, consider updating to a newer version that includes the fix for this issue. As a temporary workaround, consider restricting access to the io uring feature to minimize the risk of exploitation. Additionally, avoid using the uaddr parameter in the affected functions until the issue is resolved. At the moment, there is no information about other specific mitigation measures.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2025-12647
AZL-55712
AZL-55757
BDU:2025-15350
CVE-2024-53187
ECHO-5177-2A2C-81F3
OESA-2025-1033
OESA-2025-1035
OESA-2025-1037
OESA-2025-1078
OESA-2025-1079
OPENSUSE-SU-2025_0428-1
OPENSUSE-SU-2025_0499-1
OPENSUSE-SU-2025_0557-1
SUSE-SU-2025:0428-1
SUSE-SU-2025:0499-1
SUSE-SU-2025:0557-1
SUSE-SU-2025:0564-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0428-1
SUSE-SU-2025_0499-1
SUSE-SU-2025_0557-1
USN-7276-1
USN-7277-1
USN-7310-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu