PT-2025-3309 · Linux · Linux Kernel

Published

2025-01-06

·

Updated

2025-01-31

·

CVE-2024-56762

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.74
Description A use-after-free vulnerability has been identified in the Linux kernel's io uring/sqpoll component. This issue arises due to error handling races and can be triggered when io uring alloc task context() fails, allowing io sq thread() to run and complete before the rest of the error handling code. The vulnerability requires fault injection on the allocation side to be exploited in practice.
Recommendations For Linux kernel versions prior to 6.6.74, update to version 6.6.74 or later to resolve the issue. As a temporary workaround, consider restricting the use of the io uring/sqpoll component until a patch is available.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-56762
MGASA-2025-0030
MGASA-2025-0032

Affected Products

Linux Kernel