CVE-2024-41049
UNKNOWN
Published 2024-07-29T14:32:05.953Z
Actions:
No CVSS data available
Description
In the Linux kernel, the following vulnerability has been resolved:
filelock: fix potential use-after-free in posix_lock_inode
Light Hsieh reported a KASAN UAF warning in trace_posix_lock_inode().
The request pointer had been changed earlier to point to a lock entry
that was added to the inode's list. However, before the tracepoint could
fire, another task raced in and freed that lock.
Fix this by moving the tracepoint inside the spinlock, which should
ensure that this doesn't happen.
Available Exploits
No exploits available for this CVE.
Related News
No news articles found for this CVE.
Affected Products
Affected Versions:
117fb80cd1e63c419c7a221ce070becb4bfc7b6d
a6f4129378ca15f62cbdde09a7d3ccc35adcf49d
766e56faddbec2eaf70c9299e1c9ef74d846d32b
34bff6d850019e00001129d6de3aa4874c2cf471
74f6f5912693ce454384eaeec48705646a21c74f
74f6f5912693ce454384eaeec48705646a21c74f
74f6f5912693ce454384eaeec48705646a21c74f
e75396988bb9b3b90e6e8690604d0f566cea403a
References
Published: 2024-07-29T14:32:05.953Z
Last Modified: 2025-05-04T12:57:32.138Z
Copied to clipboard!