PT-2025-3311 · Linux+3 · Linux Kernel+3

Ming Lei

·

Published

2024-12-26

·

Updated

2025-12-07

·

CVE-2024-56764

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue has been identified in the Linux kernel's ublk module. This occurs when the add disk() function fails, potentially causing the gendisk to be freed before ublk abort requests() is called. As a result, a use-after-free condition can arise when attempting to access the disk's reference within ublk abort requests(). The issue is triggered when exiting the uring context or handling timeouts, and it affects the ublk abort requests() function, which grabs the gendisk to abort all inflight requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2025-1256
ALT-PU-2025-1925
ALT-PU-2025-3483
BDU:2025-02814
CVE-2024-56764
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7513-1
USN-7513-2
USN-7513-3
USN-7513-4
USN-7513-5
USN-7514-1
USN-7515-1
USN-7515-2
USN-7522-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Ubuntu