Review reviewHigh

CVE-2024-47750

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix Use-After-Free of rsv_qp on HIP08 Currently rsv_qp is freed before ib_unregister_device() is called on HIP08. During the time interval, users can still dereg MR and rsv_qp will be used in this process, leading to a UAF. Move the release of rsv_qp after calling ib_unregister_device() to fix it.

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.10.21
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix Use-After-Free of rsv_qp on HIP08 Currently rsv_qp is freed before ib_unregister_device() is called on HIP08. During the time interval, users can still dereg MR and rsv_qp will be used in this process, leading to a UAF. Move the release of rsv_qp after calling ib_unregister_device() to fix it.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 70f92521584f1d1e8268311ee84413307b0fdea8 < 2ccf1c75d39949d8ea043d04a2e92d7100ea723d, >= 70f92521584f1d1e8268311ee84413307b0fdea8 < d2d9c5127122745da6e887f451dd248cfeffca33, >= 70f92521584f1d1e8268311ee84413307b0fdea8 < dac2723d8bfa9cf5333f477741e6e5fa1ed34645, >= 70f92521584f1d1e8268311ee84413307b0fdea8 < 60595923371c2ebe7faf82536c47eb0c967e3425, >= 70f92521584f1d1e8268311ee84413307b0fdea8 < fd8489294dd2beefb70f12ec4f6132aeec61a4d0, >= 5.18, >= 5.18 < 6.1.113, >= 6.2 < 6.6.54, >= 6.7 < 6.10.13, >= 6.11 < 6.11.2
Fixed versions
6.1.113, 6.6.54, 6.10.13, 6.11.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2024-47750 — Linux Linux, linux kernel | SECUFOCUS NOW