PT-2025-2980 · Linux+4 · Linux Kernel+4

Published

2024-12-11

·

Updated

2026-05-26

·

CVE-2024-53687

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.74
Description The issue is related to the usage of IPIs in the kfence protect page() function, which can trigger a warning when the irqs are disabled. The flush tlb kernel range() function may use IPIs to flush the TLBs of all cores, leading to potential inaccuracies when using kfence. The vulnerability has been resolved by fixing the IPIs usage in kfence protect page().
Recommendations For Linux kernel versions prior to 6.6.74, update to version 6.6.74 or later to resolve the issue. As a temporary workaround, consider disabling the kfence protect page() function until a patch is available. Restrict access to the vulnerable flush tlb kernel range() function to minimize the risk of exploitation. Avoid using the kfence feature in the affected kernel versions until the issue is resolved.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-04894
CVE-2024-53687
ECHO-8148-BB51-CD52
MGASA-2025-0030
MGASA-2025-0032
OESA-2025-1248
OESA-2025-1249
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7513-1
USN-7513-2
USN-7513-3
USN-7513-4
USN-7513-5
USN-7514-1
USN-7515-1
USN-7515-2
USN-7522-1
USN-7523-1
USN-7524-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Ubuntu