CVE-2024-49924 (GCVE-0-2024-49924)
Vulnerability from cvelistv5
Published
2024-10-21 18:01
Modified
2026-08-05 11:40
Summary
In the Linux kernel, the following vulnerability has been resolved: fbdev: pxafb: Fix possible use after free in pxafb_task() In the pxafb_probe function, it calls the pxafb_init_fbinfo function, after which &fbi->task is associated with pxafb_task. Moreover, within this pxafb_init_fbinfo function, the pxafb_blank function within the &pxafb_ops struct is capable of scheduling work. If we remove the module which will call pxafb_remove to make cleanup, it will call unregister_framebuffer function which can call do_unregister_framebuffer to free fbi->fb through put_fb_info(fb_info), while the work mentioned above will be used. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | pxafb_task pxafb_remove | unregister_framebuffer(info) | do_unregister_framebuffer(fb_info) | put_fb_info(fb_info) | // free fbi->fb | set_ctrlr_state(fbi, state) | __pxafb_lcd_power(fbi, 0) | fbi->lcd_power(on, &fbi->fb.var) | //use fbi->fb Fix it by ensuring that the work is canceled before proceeding with the cleanup in pxafb_remove. Note that only root user can remove the driver at runtime.
Impacted products
Vendor Product Version
Linux Linux Version: 9f17f2874834f4cdbe48cc05676d8f7558793204
Version: 9f17f2874834f4cdbe48cc05676d8f7558793204
Version: 9f17f2874834f4cdbe48cc05676d8f7558793204
Version: 9f17f2874834f4cdbe48cc05676d8f7558793204
Version: 9f17f2874834f4cdbe48cc05676d8f7558793204
Version: 9f17f2874834f4cdbe48cc05676d8f7558793204
Version: 9f17f2874834f4cdbe48cc05676d8f7558793204
Version: 9f17f2874834f4cdbe48cc05676d8f7558793204
Version: 9f17f2874834f4cdbe48cc05676d8f7558793204
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-49924",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-10-22T13:39:57.349772Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-10-22T13:48:44.187Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:23:13.319Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/video/fbdev/pxafb.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "e657fa2df4429f3805a9b3e47fb1a4a1b02a72bd",
              "status": "affected",
              "version": "9f17f2874834f4cdbe48cc05676d8f7558793204",
              "versionType": "git"
            },
            {
              "lessThan": "6d0a07f68b66269e167def6c0b90a219cd3e7473",
              "status": "affected",
              "version": "9f17f2874834f4cdbe48cc05676d8f7558793204",
              "versionType": "git"
            },
            {
              "lessThan": "e6897e299f57b103e999e62010b88e363b3eebae",
              "status": "affected",
              "version": "9f17f2874834f4cdbe48cc05676d8f7558793204",
              "versionType": "git"
            },
            {
              "lessThan": "4cda484e584be34d55ee17436ebf7ad11922b97a",
              "status": "affected",
              "version": "9f17f2874834f4cdbe48cc05676d8f7558793204",
              "versionType": "git"
            },
            {
              "lessThan": "3c0d416eb4bef705f699213cee94bf54b6acdacd",
              "status": "affected",
              "version": "9f17f2874834f4cdbe48cc05676d8f7558793204",
              "versionType": "git"
            },
            {
              "lessThan": "fdda354f60a576d52dcf90351254714681df4370",
              "status": "affected",
              "version": "9f17f2874834f4cdbe48cc05676d8f7558793204",
              "versionType": "git"
            },
            {
              "lessThan": "aaadc0cb05c999ccd8898a03298b7e5c31509b08",
              "status": "affected",
              "version": "9f17f2874834f4cdbe48cc05676d8f7558793204",
              "versionType": "git"
            },
            {
              "lessThan": "a3a855764dbacbdb1cc51e15dc588f2d21c93e0e",
              "status": "affected",
              "version": "9f17f2874834f4cdbe48cc05676d8f7558793204",
              "versionType": "git"
            },
            {
              "lessThan": "4a6921095eb04a900e0000da83d9475eb958e61e",
              "status": "affected",
              "version": "9f17f2874834f4cdbe48cc05676d8f7558793204",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/video/fbdev/pxafb.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.27"
            },
            {
              "lessThan": "2.6.27",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.323",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.285",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.227",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.168",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.113",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.55",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.14",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.323",
                  "versionStartIncluding": "2.6.27",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.285",
                  "versionStartIncluding": "2.6.27",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.227",
                  "versionStartIncluding": "2.6.27",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.168",
                  "versionStartIncluding": "2.6.27",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.113",
                  "versionStartIncluding": "2.6.27",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.55",
                  "versionStartIncluding": "2.6.27",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.14",
                  "versionStartIncluding": "2.6.27",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.3",
                  "versionStartIncluding": "2.6.27",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "2.6.27",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: pxafb: Fix possible use after free in pxafb_task()\n\nIn the pxafb_probe function, it calls the pxafb_init_fbinfo function,\nafter which \u0026fbi-\u003etask is associated with pxafb_task. Moreover,\nwithin this pxafb_init_fbinfo function, the pxafb_blank function\nwithin the \u0026pxafb_ops struct is capable of scheduling work.\n\nIf we remove the module which will call pxafb_remove to make cleanup,\nit will call unregister_framebuffer function which can call\ndo_unregister_framebuffer to free fbi-\u003efb through\nput_fb_info(fb_info), while the work mentioned above will be used.\nThe sequence of operations that may lead to a UAF bug is as follows:\n\nCPU0                                                CPU1\n\n                                   | pxafb_task\npxafb_remove                       |\nunregister_framebuffer(info)       |\ndo_unregister_framebuffer(fb_info) |\nput_fb_info(fb_info)               |\n// free fbi-\u003efb                    | set_ctrlr_state(fbi, state)\n                                   | __pxafb_lcd_power(fbi, 0)\n                                   | fbi-\u003elcd_power(on, \u0026fbi-\u003efb.var)\n                                   | //use fbi-\u003efb\n\nFix it by ensuring that the work is canceled before proceeding\nwith the cleanup in pxafb_remove.\n\nNote that only root user can remove the driver at runtime."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is reached entirely through local interfaces \u2014 `FBIOBLANK`/`FBIOPUT_VSCREENINFO` ioctls on `/dev/fbN` to queue `fbi-\u003etask`, and platform driver unbind/`rmmod` to free the devm-allocated `pxafb_info`. No network or physical device manipulation is involved.\nAC:L - The attacker deterministically arms the race by repeatedly queueing `pxafb_task` via `FBIOBLANK`, and the racing work sleeps up to 200 ms in `wait_for_completion_timeout(\u0026fbi-\u003edisable_done, ...)` inside `pxafb_disable_controller()`, giving an enormous, reliably winnable window. No error path, unusual memory layout, or non-default configuration is required \u2014 `CONFIG_FB_PXA` is standard and tristate on every PXA platform.\nPR:L - An ordinary unprivileged user needs only DAC access to `/dev/fb0` \u2014 which requires no capability and is routinely granted on the embedded PXA handhelds and panel devices this driver targets \u2014 to queue the work and groom the slab that backs the freed `pxafb_info`. This matches this CNA\u0027s established treatment of driver-teardown UAFs (e.g. CVE-2025-21976, hyperv_fb), where `PR:H` is reserved for cases that cross a VM/container security boundary.\nUI:N - No victim action such as opening a file or mounting a filesystem is needed; the pending work is also queued automatically by the fbcon console-blank timer and by `pxafb_set_par()`, so the race can be live without any interactive user.\nS:U - The corrupted memory and the resulting code execution are both in the host kernel\u0027s own security authority, with no VM, IOMMU, or sandbox boundary crossed.\nC:H - The use-after-free lets the attacker control the contents of the reallocated `pxafb_info`, including `fbi-\u003emmio_base`, which `lcd_readl()` dereferences \u2014 yielding an attacker-directed read primitive that, combined with the hijacked control flow, permits disclosure of arbitrary kernel memory.\nI:H - `__pxafb_lcd_power()` and `__pxafb_backlight_power()` call `fbi-\u003elcd_power()` / `fbi-\u003ebacklight_power()` \u2014 function pointers read straight out of the freed allocation \u2014 and `lcd_writel()` performs `__raw_writel()` to an address taken from the same freed object, giving both control-flow hijack and an arbitrary write.\nA:H - Even without successful exploitation the UAF reliably oopses the kernel \u2014 dereferencing a freed `mmio_base`, locking a freed mutex, or on `rmmod` executing `pxafb_task` text that has already been unmapped with the module."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:40:27.887Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e657fa2df4429f3805a9b3e47fb1a4a1b02a72bd"
        },
        {
          "url": "https://git.kernel.org/stable/c/6d0a07f68b66269e167def6c0b90a219cd3e7473"
        },
        {
          "url": "https://git.kernel.org/stable/c/e6897e299f57b103e999e62010b88e363b3eebae"
        },
        {
          "url": "https://git.kernel.org/stable/c/4cda484e584be34d55ee17436ebf7ad11922b97a"
        },
        {
          "url": "https://git.kernel.org/stable/c/3c0d416eb4bef705f699213cee94bf54b6acdacd"
        },
        {
          "url": "https://git.kernel.org/stable/c/fdda354f60a576d52dcf90351254714681df4370"
        },
        {
          "url": "https://git.kernel.org/stable/c/aaadc0cb05c999ccd8898a03298b7e5c31509b08"
        },
        {
          "url": "https://git.kernel.org/stable/c/a3a855764dbacbdb1cc51e15dc588f2d21c93e0e"
        },
        {
          "url": "https://git.kernel.org/stable/c/4a6921095eb04a900e0000da83d9475eb958e61e"
        }
      ],
      "title": "fbdev: pxafb: Fix possible use after free in pxafb_task()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-49924",
    "datePublished": "2024-10-21T18:01:49.076Z",
    "dateReserved": "2024-10-21T12:17:06.036Z",
    "dateUpdated": "2026-08-05T11:40:27.887Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T22:23:13.319Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-49924\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-10-22T13:39:57.349772Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-10-22T13:40:00.525Z\"}}], \"cna\": {\"title\": \"fbdev: pxafb: Fix possible use after free in pxafb_task()\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"9f17f2874834f4cdbe48cc05676d8f7558793204\", \"lessThan\": \"e657fa2df4429f3805a9b3e47fb1a4a1b02a72bd\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"9f17f2874834f4cdbe48cc05676d8f7558793204\", \"lessThan\": \"6d0a07f68b66269e167def6c0b90a219cd3e7473\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"9f17f2874834f4cdbe48cc05676d8f7558793204\", \"lessThan\": \"e6897e299f57b103e999e62010b88e363b3eebae\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"9f17f2874834f4cdbe48cc05676d8f7558793204\", \"lessThan\": \"4cda484e584be34d55ee17436ebf7ad11922b97a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"9f17f2874834f4cdbe48cc05676d8f7558793204\", \"lessThan\": \"3c0d416eb4bef705f699213cee94bf54b6acdacd\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"9f17f2874834f4cdbe48cc05676d8f7558793204\", \"lessThan\": \"fdda354f60a576d52dcf90351254714681df4370\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"9f17f2874834f4cdbe48cc05676d8f7558793204\", \"lessThan\": \"aaadc0cb05c999ccd8898a03298b7e5c31509b08\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"9f17f2874834f4cdbe48cc05676d8f7558793204\", \"lessThan\": \"a3a855764dbacbdb1cc51e15dc588f2d21c93e0e\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"9f17f2874834f4cdbe48cc05676d8f7558793204\", \"lessThan\": \"4a6921095eb04a900e0000da83d9475eb958e61e\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/video/fbdev/pxafb.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"2.6.27\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"2.6.27\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"4.19.323\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"4.19.*\"}, {\"status\": \"unaffected\", \"version\": \"5.4.285\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.227\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.168\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.113\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.55\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10.14\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.10.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.3\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/video/fbdev/pxafb.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/e657fa2df4429f3805a9b3e47fb1a4a1b02a72bd\"}, {\"url\": \"https://git.kernel.org/stable/c/6d0a07f68b66269e167def6c0b90a219cd3e7473\"}, {\"url\": \"https://git.kernel.org/stable/c/e6897e299f57b103e999e62010b88e363b3eebae\"}, {\"url\": \"https://git.kernel.org/stable/c/4cda484e584be34d55ee17436ebf7ad11922b97a\"}, {\"url\": \"https://git.kernel.org/stable/c/3c0d416eb4bef705f699213cee94bf54b6acdacd\"}, {\"url\": \"https://git.kernel.org/stable/c/fdda354f60a576d52dcf90351254714681df4370\"}, {\"url\": \"https://git.kernel.org/stable/c/aaadc0cb05c999ccd8898a03298b7e5c31509b08\"}, {\"url\": \"https://git.kernel.org/stable/c/a3a855764dbacbdb1cc51e15dc588f2d21c93e0e\"}, {\"url\": \"https://git.kernel.org/stable/c/4a6921095eb04a900e0000da83d9475eb958e61e\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nfbdev: pxafb: Fix possible use after free in pxafb_task()\\n\\nIn the pxafb_probe function, it calls the pxafb_init_fbinfo function,\\nafter which \u0026fbi-\u003etask is associated with pxafb_task. Moreover,\\nwithin this pxafb_init_fbinfo function, the pxafb_blank function\\nwithin the \u0026pxafb_ops struct is capable of scheduling work.\\n\\nIf we remove the module which will call pxafb_remove to make cleanup,\\nit will call unregister_framebuffer function which can call\\ndo_unregister_framebuffer to free fbi-\u003efb through\\nput_fb_info(fb_info), while the work mentioned above will be used.\\nThe sequence of operations that may lead to a UAF bug is as follows:\\n\\nCPU0                                                CPU1\\n\\n                                   | pxafb_task\\npxafb_remove                       |\\nunregister_framebuffer(info)       |\\ndo_unregister_framebuffer(fb_info) |\\nput_fb_info(fb_info)               |\\n// free fbi-\u003efb                    | set_ctrlr_state(fbi, state)\\n                                   | __pxafb_lcd_power(fbi, 0)\\n                                   | fbi-\u003elcd_power(on, \u0026fbi-\u003efb.var)\\n                                   | //use fbi-\u003efb\\n\\nFix it by ensuring that the work is canceled before proceeding\\nwith the cleanup in pxafb_remove.\\n\\nNote that only root user can remove the driver at runtime.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.19.323\", \"versionStartIncluding\": \"2.6.27\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.285\", \"versionStartIncluding\": \"2.6.27\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.227\", \"versionStartIncluding\": \"2.6.27\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.168\", \"versionStartIncluding\": \"2.6.27\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.113\", \"versionStartIncluding\": \"2.6.27\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.55\", \"versionStartIncluding\": \"2.6.27\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10.14\", \"versionStartIncluding\": \"2.6.27\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.3\", \"versionStartIncluding\": \"2.6.27\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12\", \"versionStartIncluding\": \"2.6.27\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-01-05T10:54:21.310Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-49924\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-01-05T10:54:21.310Z\", \"dateReserved\": \"2024-10-21T12:17:06.036Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-10-21T18:01:49.076Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…