PT-2024-9053 · Linux+9 · Linux Kernel+9

Syzbot

·

Published

2024-05-05

·

Updated

2026-03-14

·

CVE-2024-38580

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the epoll component in the Linux kernel, where a file pointer may race with the last 'fput()' call, causing the file reference count to go down to zero. This results in the file pointer being dead, and any use of it won't actually get a reference to the file. The problem occurs when epoll calls out to vfs poll() with a file pointer that may be torn down due to a racing condition. To fix this, a valid reference on the file pointer is ensured before calling down to vfs poll() from the epoll routines.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4928
ALSA-2025_16880
BDU:2024-10735
CVE-2024-38580
INFSA-2024_4928
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-2076
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
RHSA-2024:4928
RHSA-2024_4928
RLSA-2024:4928
RXSA-2024:4928
SUSE-SU-2024:2360-1
SUSE-SU-2024:2372-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2561-1
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1
USN-7007-1
USN-7007-2
USN-7007-3
USN-7009-1
USN-7009-2
USN-7019-1

Affected Products

Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu