PT-2024-5415 · Linux+6 · Linux Kernel+6
Dicken.Ding
·
Published
2024-05-24
·
Updated
2025-09-29
·
CVE-2024-38385
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to a use-after-free vulnerability in the
irq find at or after() function. This function dereferences an interrupt descriptor returned by mt find() without holding the necessary locks, allowing the descriptor to be freed between mt find() and the dereference. The vulnerability can be exploited to impact the confidentiality, integrity, and availability of protected information. The use-after-free is reported by KASAN, with a call trace involving irq get next irq(), show stat(), seq read iter(), proc reg read iter(), and vfs read(). The vulnerability is caused by the lack of a RCU read lock section when accessing the interrupt descriptor.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu