VDB

DEBIAN-CVE-2024-38545

DEBIAN-CVE-2024-38545 PUBLISHED CVSS 7.800000190734863 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix UAF for cq async event The refcount of CQ is not protected by locks. When CQ asynchronous events and CQ destruction are concurrent, CQ may have been released, which will cause UAF. Use the xa_lock() to protect the CQ refcount.

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:12linux6.1.94-1, 6.1.90-1, 6.1.90-1
Debian:13linux0, 0
Debian:11linux6.18.9-1, 6.5.3-1, 6.18.14-1
Debian:14linux0, 0

Timeline

  • Jun 19, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›