SB2024123079 - Use-after-free in Linux kernel sunrpc
Published: December 30, 2024 Updated: May 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2024-53174)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the c_show() function in net/sunrpc/cache.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/02999e135b013d85c6df738746e8e24699befee4
- https://git.kernel.org/stable/c/068c0b50f3f700b94f78850834cd91ae3b34c2c1
- https://git.kernel.org/stable/c/2862eee078a4d2d1f584e7f24fa50dddfa5f3471
- https://git.kernel.org/stable/c/acfaf37888e0f0732fb6a50ff093dce6d99994d0
- https://git.kernel.org/stable/c/c7dac3af57e38b2054f990e573256d90bf887958
- https://git.kernel.org/stable/c/d882e2b7fad3f5e5fac66184a347f408813f654a
- https://git.kernel.org/stable/c/e9be26735d055c42543a4d047a769cc6d0fb1504
- https://git.kernel.org/stable/c/ec305f303bf070b4f6896b7a76009f702956d402
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.11.11