Review reviewHigh

CVE-2024-47747

Linux Linux, RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family

In the Linux kernel, the following vulnerability has been resolved: net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition In the ether3_probe function, a timer is initialized with a callback function ether3_ledoff, bound to &prev(dev)->timer. Once the timer is started, there is a risk of a race condition if the module or device is removed, triggering the ether3_remove function to perform cleanup. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | ether3_ledoff ether3_remove | free_netdev(dev); | put_devic | kfree(dev); | | ether3_ou...

CVSS
7
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.10.21
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition In the ether3_probe function, a timer is initialized with a callback function ether3_ledoff, bound to &prev(dev)->timer. Once the timer is started, there is a risk of a race condition if the module or device is removed, triggering the ether3_remove function to perform cleanup. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | ether3_ledoff ether3_remove | free_netdev(dev); | put_devic | kfree(dev); | | ether3_ou...

Affected product and versions

Product
Linux Linux, RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family
Affected versions
>= 6fd9c53f71862a4797b7ed8a5de80e2c64829f56 < 25d559ed2beec9b34045886100dac46d1ad92eba, >= 6fd9c53f71862a4797b7ed8a5de80e2c64829f56 < b5a84b6c772564c8359a9a0fbaeb2a2944aa1ee9, >= 6fd9c53f71862a4797b7ed8a5de80e2c64829f56 < 338a0582b28e69460df03af50e938b86b4206353, >= 6fd9c53f71862a4797b7ed8a5de80e2c64829f56 < 822c7bb1f6f8b0331e8d1927151faf8db3b33afd, >= 6fd9c53f71862a4797b7ed8a5de80e2c64829f56 < 1c57d61a43293252ad732007c7070fdb112545fd, >= 6fd9c53f71862a4797b7ed8a5de80e2c64829f56 < d2abc379071881798d20e2ac1d332ad855ae22f3, >= 6fd9c53f71862a4797b7ed8a5de80e2c64829f56 < 516dbc6d16637430808c39568cbb6b841d32b55b, >= 6fd9c53f71862a4797b7ed8a5de80e2c64829f56 < 77a77331cef0a219b8dd91361435eeef04cb741c, >= 6fd9c53f71862a4797b7ed8a5de80e2c64829f56 < b5109b60ee4fcb2f2bb24f589575e10cc5283ad4, >= 4.15, < V3.2, >= 4.15 < 5.10.227, >= 5.11 < 5.15.168, >= 5.16 < 6.1.113, >= 6.2 < 6.6.54, >= 6.7 < 6.10.13, >= 6.11 < 6.11.2
Fixed versions
5.10.227, 5.15.168, 6.1.113, 6.6.54, 6.10.13, 6.11.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, RUGGEDCOM RST2428P, SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416