Review reviewHigh

CVE-2024-49854

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix uaf for accessing waker_bfqq after splitting After commit 42c306ed7233 ("block, bfq: don't break merge chain in bfq_split_bfqq()"), if the current procress is the last holder of bfqq, the bfqq can be freed after bfq_split_bfqq(). Hence recored the bfqq and then access bfqq->waker_bfqq may trigger UAF. What's more, the waker_bfqq may in the merge chain of bfqq, hence just recored waker_bfqq is still not safe. Fix the problem by adding a helper bfq_waker_bfqq() to check if bfqq->waker_bfqq is in the merge chai...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.10.21
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix uaf for accessing waker_bfqq after splitting After commit 42c306ed7233 ("block, bfq: don't break merge chain in bfq_split_bfqq()"), if the current procress is the last holder of bfqq, the bfqq can be freed after bfq_split_bfqq(). Hence recored the bfqq and then access bfqq->waker_bfqq may trigger UAF. What's more, the waker_bfqq may in the merge chain of bfqq, hence just recored waker_bfqq is still not safe. Fix the problem by adding a helper bfq_waker_bfqq() to check if bfqq->waker_bfqq is in the merge chai...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= e0c20d88b7dce85d2703bb6ba77bf359959675cd < 63a07379fdb6c72450cb05294461c6016b8b7726, >= de6c5e3a456019d2182e345730e59721714fa0b5 < de0456460f2abf921e356ed2bd8da87a376680bd, >= 19f3bec2ac4be329b9bd12b18a989b867618d2d8 < 0780451f03bf518bc032a7c584de8f92e2d39d7f, >= 13b3d0e8cb121f99b11918a0d4bcc1ce4647d352 < 0b8bda0ff17156cd3f60944527c9d8c9f99f1583, >= 4780f50ea50cfe8e89fc3747bf3dd155488433bb < cae58d19121a70329cf971359e2518c93fec04fe, >= 42c306ed723321af4003b2a41bb73728cab54f85 < 1ba0403ac6447f2d63914fb760c44a3b19c44eaf, >= 9e813033594b141f61ff0ef0cfaaef292564b041, >= 3a5f45a4ad4e1fd36b0a998eef03d76a4f02a2a8, >= 3630a18846c7853aa326d3b42fd0a855af7b41bc, >= 4.19.323 < 4.20, >= 5.4.285 < 5.5, >= 5.10.227 < 5.11, >= 5.10.227 < 5.15.168, >= 5.16 < 6.1.113, >= 6.2 < 6.6.54, >= 6.7 < 6.10.13, >= 6.11 < 6.11.2
Fixed versions
5.15.168, 6.1.113, 6.6.54, 6.10.13, 6.11.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416