CVE-2024-53174 (GCVE-0-2024-53174)
Vulnerability from cvelistv5
Published
2024-12-27 13:49
Modified
2026-08-05 11:44
Summary
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: make sure cache entry active before cache_show The function `c_show` was called with protection from RCU. This only ensures that `cp` will not be freed. Therefore, the reference count for `cp` can drop to zero, which will trigger a refcount use-after-free warning when `cache_get` is called. To resolve this issue, use `cache_get_rcu` to ensure that `cp` remains active. ------------[ cut here ]------------ refcount_t: addition on 0; use-after-free. WARNING: CPU: 7 PID: 822 at lib/refcount.c:25 refcount_warn_saturate+0xb1/0x120 CPU: 7 UID: 0 PID: 822 Comm: cat Not tainted 6.12.0-rc3+ #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014 RIP: 0010:refcount_warn_saturate+0xb1/0x120 Call Trace: <TASK> c_show+0x2fc/0x380 [sunrpc] seq_read_iter+0x589/0x770 seq_read+0x1e5/0x270 proc_reg_read+0xe1/0x140 vfs_read+0x125/0x530 ksys_read+0xc1/0x160 do_syscall_64+0x5f/0x170 entry_SYSCALL_64_after_hwframe+0x76/0x7e
Impacted products
Vendor Product Version
Linux Linux Version: d48cf356a13073853f19be6ca5ebbecfc2762ebe
Version: d48cf356a13073853f19be6ca5ebbecfc2762ebe
Version: d48cf356a13073853f19be6ca5ebbecfc2762ebe
Version: d48cf356a13073853f19be6ca5ebbecfc2762ebe
Version: d48cf356a13073853f19be6ca5ebbecfc2762ebe
Version: d48cf356a13073853f19be6ca5ebbecfc2762ebe
Version: d48cf356a13073853f19be6ca5ebbecfc2762ebe
Version: d48cf356a13073853f19be6ca5ebbecfc2762ebe
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 7.8,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-53174",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-02-11T15:43:35.253566Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-416",
                "description": "CWE-416 Use After Free",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-02-11T15:45:26.877Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T20:47:09.594Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/sunrpc/cache.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "e9be26735d055c42543a4d047a769cc6d0fb1504",
              "status": "affected",
              "version": "d48cf356a13073853f19be6ca5ebbecfc2762ebe",
              "versionType": "git"
            },
            {
              "lessThan": "02999e135b013d85c6df738746e8e24699befee4",
              "status": "affected",
              "version": "d48cf356a13073853f19be6ca5ebbecfc2762ebe",
              "versionType": "git"
            },
            {
              "lessThan": "c7dac3af57e38b2054f990e573256d90bf887958",
              "status": "affected",
              "version": "d48cf356a13073853f19be6ca5ebbecfc2762ebe",
              "versionType": "git"
            },
            {
              "lessThan": "068c0b50f3f700b94f78850834cd91ae3b34c2c1",
              "status": "affected",
              "version": "d48cf356a13073853f19be6ca5ebbecfc2762ebe",
              "versionType": "git"
            },
            {
              "lessThan": "acfaf37888e0f0732fb6a50ff093dce6d99994d0",
              "status": "affected",
              "version": "d48cf356a13073853f19be6ca5ebbecfc2762ebe",
              "versionType": "git"
            },
            {
              "lessThan": "ec305f303bf070b4f6896b7a76009f702956d402",
              "status": "affected",
              "version": "d48cf356a13073853f19be6ca5ebbecfc2762ebe",
              "versionType": "git"
            },
            {
              "lessThan": "d882e2b7fad3f5e5fac66184a347f408813f654a",
              "status": "affected",
              "version": "d48cf356a13073853f19be6ca5ebbecfc2762ebe",
              "versionType": "git"
            },
            {
              "lessThan": "2862eee078a4d2d1f584e7f24fa50dddfa5f3471",
              "status": "affected",
              "version": "d48cf356a13073853f19be6ca5ebbecfc2762ebe",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/sunrpc/cache.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.20"
            },
            {
              "lessThan": "4.20",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.287",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.231",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.174",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.120",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.64",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.13",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.287",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.231",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.174",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.120",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.64",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.11",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.2",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: make sure cache entry active before cache_show\n\nThe function `c_show` was called with protection from RCU. This only\nensures that `cp` will not be freed. Therefore, the reference count for\n`cp` can drop to zero, which will trigger a refcount use-after-free\nwarning when `cache_get` is called. To resolve this issue, use\n`cache_get_rcu` to ensure that `cp` remains active.\n\n------------[ cut here ]------------\nrefcount_t: addition on 0; use-after-free.\nWARNING: CPU: 7 PID: 822 at lib/refcount.c:25\nrefcount_warn_saturate+0xb1/0x120\nCPU: 7 UID: 0 PID: 822 Comm: cat Not tainted 6.12.0-rc3+ #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n1.16.1-2.fc37 04/01/2014\nRIP: 0010:refcount_warn_saturate+0xb1/0x120\n\nCall Trace:\n \u003cTASK\u003e\n c_show+0x2fc/0x380 [sunrpc]\n seq_read_iter+0x589/0x770\n seq_read+0x1e5/0x270\n proc_reg_read+0xe1/0x140\n vfs_read+0x125/0x530\n ksys_read+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is triggered by a read() syscall on the procfs file /proc/net/rpc/*/content (path proc_reg_read \u2192 seq_read \u2192 c_show); it requires local access, not network reachability.\nAC:L - The attacker controls both sides of the race \u2014 populating entries by writing the cache\u0027s channel file and dropping their refcount by writing flush, while looping reads of content \u2014 so the UAF window can be hit repeatably; per guidance, attacker-controlled races are Low.\nPR:L - In the init namespace content is root-only (mode 400), but an unprivileged user can create a user+network namespace (unshare -Ur; unshare -n) and become root of the fresh per-netns sunrpc caches, gaining read access to content and write access to channel/flush \u2014 empirically verified. This is Low, not High.\nUI:N - The attacker performs the cache population, flush, and read entirely on its own; no victim interaction is needed.\nS:U - The use-after-free is confined to the kernel\u0027s own memory/authority; no crossing of a security boundary such as VM or IOMMU is involved.\nC:H - The use-after-free lets c_show read fields of a potentially freed and reallocated cache_head and emit them into the content output the attacker reads, enabling disclosure of freed/reused kernel memory.\nI:H - A use-after-free on the cache_head (with cache_check/cache_put operating on freed, potentially reallocated memory) provides a corruption primitive; per guidance UAFs are scored High for integrity.\nA:H - The use-after-free corrupts refcounting and touches freed memory, readily causing an oops/panic; per guidance any UAF/crash is High."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:44:21.962Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e9be26735d055c42543a4d047a769cc6d0fb1504"
        },
        {
          "url": "https://git.kernel.org/stable/c/02999e135b013d85c6df738746e8e24699befee4"
        },
        {
          "url": "https://git.kernel.org/stable/c/c7dac3af57e38b2054f990e573256d90bf887958"
        },
        {
          "url": "https://git.kernel.org/stable/c/068c0b50f3f700b94f78850834cd91ae3b34c2c1"
        },
        {
          "url": "https://git.kernel.org/stable/c/acfaf37888e0f0732fb6a50ff093dce6d99994d0"
        },
        {
          "url": "https://git.kernel.org/stable/c/ec305f303bf070b4f6896b7a76009f702956d402"
        },
        {
          "url": "https://git.kernel.org/stable/c/d882e2b7fad3f5e5fac66184a347f408813f654a"
        },
        {
          "url": "https://git.kernel.org/stable/c/2862eee078a4d2d1f584e7f24fa50dddfa5f3471"
        }
      ],
      "title": "SUNRPC: make sure cache entry active before cache_show",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-53174",
    "datePublished": "2024-12-27T13:49:18.892Z",
    "dateReserved": "2024-11-19T17:17:25.007Z",
    "dateUpdated": "2026-08-05T11:44:21.962Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html\"}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T20:47:09.594Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 7.8, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"HIGH\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-53174\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-02-11T15:43:35.253566Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-416\", \"description\": \"CWE-416 Use After Free\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-02-11T15:43:36.911Z\"}}], \"cna\": {\"title\": \"SUNRPC: make sure cache entry active before cache_show\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"d48cf356a13073853f19be6ca5ebbecfc2762ebe\", \"lessThan\": \"e9be26735d055c42543a4d047a769cc6d0fb1504\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d48cf356a13073853f19be6ca5ebbecfc2762ebe\", \"lessThan\": \"02999e135b013d85c6df738746e8e24699befee4\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d48cf356a13073853f19be6ca5ebbecfc2762ebe\", \"lessThan\": \"c7dac3af57e38b2054f990e573256d90bf887958\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d48cf356a13073853f19be6ca5ebbecfc2762ebe\", \"lessThan\": \"068c0b50f3f700b94f78850834cd91ae3b34c2c1\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d48cf356a13073853f19be6ca5ebbecfc2762ebe\", \"lessThan\": \"acfaf37888e0f0732fb6a50ff093dce6d99994d0\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d48cf356a13073853f19be6ca5ebbecfc2762ebe\", \"lessThan\": \"ec305f303bf070b4f6896b7a76009f702956d402\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d48cf356a13073853f19be6ca5ebbecfc2762ebe\", \"lessThan\": \"d882e2b7fad3f5e5fac66184a347f408813f654a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d48cf356a13073853f19be6ca5ebbecfc2762ebe\", \"lessThan\": \"2862eee078a4d2d1f584e7f24fa50dddfa5f3471\", \"versionType\": \"git\"}], \"programFiles\": [\"net/sunrpc/cache.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.20\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.20\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.4.287\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.231\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.174\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.120\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.64\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.11\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.12.*\"}, {\"status\": \"unaffected\", \"version\": \"6.13\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"net/sunrpc/cache.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/e9be26735d055c42543a4d047a769cc6d0fb1504\"}, {\"url\": \"https://git.kernel.org/stable/c/02999e135b013d85c6df738746e8e24699befee4\"}, {\"url\": \"https://git.kernel.org/stable/c/c7dac3af57e38b2054f990e573256d90bf887958\"}, {\"url\": \"https://git.kernel.org/stable/c/068c0b50f3f700b94f78850834cd91ae3b34c2c1\"}, {\"url\": \"https://git.kernel.org/stable/c/acfaf37888e0f0732fb6a50ff093dce6d99994d0\"}, {\"url\": \"https://git.kernel.org/stable/c/ec305f303bf070b4f6896b7a76009f702956d402\"}, {\"url\": \"https://git.kernel.org/stable/c/d882e2b7fad3f5e5fac66184a347f408813f654a\"}, {\"url\": \"https://git.kernel.org/stable/c/2862eee078a4d2d1f584e7f24fa50dddfa5f3471\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nSUNRPC: make sure cache entry active before cache_show\\n\\nThe function `c_show` was called with protection from RCU. This only\\nensures that `cp` will not be freed. Therefore, the reference count for\\n`cp` can drop to zero, which will trigger a refcount use-after-free\\nwarning when `cache_get` is called. To resolve this issue, use\\n`cache_get_rcu` to ensure that `cp` remains active.\\n\\n------------[ cut here ]------------\\nrefcount_t: addition on 0; use-after-free.\\nWARNING: CPU: 7 PID: 822 at lib/refcount.c:25\\nrefcount_warn_saturate+0xb1/0x120\\nCPU: 7 UID: 0 PID: 822 Comm: cat Not tainted 6.12.0-rc3+ #1\\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\\n1.16.1-2.fc37 04/01/2014\\nRIP: 0010:refcount_warn_saturate+0xb1/0x120\\n\\nCall Trace:\\n \u003cTASK\u003e\\n c_show+0x2fc/0x380 [sunrpc]\\n seq_read_iter+0x589/0x770\\n seq_read+0x1e5/0x270\\n proc_reg_read+0xe1/0x140\\n vfs_read+0x125/0x530\\n ksys_read+0xc1/0x160\\n do_syscall_64+0x5f/0x170\\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.287\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.231\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.174\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.120\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.64\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.11\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12.2\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.13\", \"versionStartIncluding\": \"4.20\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-01-05T10:55:39.550Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-53174\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-01-05T10:55:39.550Z\", \"dateReserved\": \"2024-11-19T17:17:25.007Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-12-27T13:49:18.892Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…