CVE & CISA-KEV Catalog

CVE-2024-49953

MEDIUM
5.5
CVSS v3
NVD

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix crash caused by calling __xfrm_state_delete() twice The km.state is not checked in driver's delayed work. When xfrm_state_check_expire() is called, the state can be reset to XFRM_STATE_EXPIRED, even if it is XFRM_STATE_DEAD already. This happens when xfrm state is deleted, but not freed yet. As __xfrm_state_delete() is called again in xfrm timer, the following crash occurs. To fix this issue, skip xfrm_state_check_expire() if km.state is not XFRM_STATE_VALID. Oops: general protection fault, probably for non-canonical address 0xdead000000000108: 0000 [#1] SMP CPU: 5 UID: 0 PID: 7448 Comm: kworker/u102:2 Not tainted 6.11.0-rc2+ #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 Workqueue: mlx5e_ipsec: eth%d mlx5e_ipsec_handle_sw_limits [mlx5_core] RIP: 0010:__xfrm_state_delete+0x3d/0x1b0 Code: 0f 84 8b 01 00 00 48 89 fd c6 87 c8 00 00 00 05 48 8d bb 40 10 00 00 e8 11 04 1a 00 48 8b 95 b8 00 00 00 48 8b 85 c0 00 00 00 <48> 89 42 08 48 89 10 48 8b 55 10 48 b8 00 01 00 00 00 00 ad de 48 RSP: 0018:ffff88885f945ec8 EFLAGS: 00010246 RAX: dead000000000122 RBX: ffffffff82afa940 RCX: 0000000000000036 RDX: dead000000000100 RSI: 0000000000000000 RDI: ffffffff82afb980 RBP: ffff888109a20340 R08: ffff88885f945ea0 R09: 0000000000000000 R10: 0000000000000000 R11: ffff88885f945ff8 R12: 0000000000000246 R13: ffff888109a20340 R14: ffff88885f95f420 R15: ffff88885f95f400 FS: 0000000000000000(0000) GS:ffff88885f940000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f2163102430 CR3: 00000001128d6001 CR4: 0000000000370eb0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <IRQ> ? die_addr+0x33/0x90 ? exc_general_protection+0x1a2/0x390 ? asm_exc_general_protection+0x22/0x30 ? __xfrm_state_delete+0x3d/0x1b0 ? __xfrm_state_delete+0x2f/0x1b0 xfrm_timer_handler+0x174/0x350 ? __xfrm_state_delete+0x1b0/0x1b0 __hrtimer_run_queues+0x121/0x270 hrtimer_run_softirq+0x88/0xd0 handle_softirqs+0xcc/0x270 do_softirq+0x3c/0x50 </IRQ> <TASK> __local_bh_enable_ip+0x47/0x50 mlx5e_ipsec_handle_sw_limits+0x7d/0x90 [mlx5_core] process_one_work+0x137/0x2d0 worker_thread+0x28d/0x3a0 ? rescuer_thread+0x480/0x480 kthread+0xb8/0xe0 ? kthread_park+0x80/0x80 ret_from_fork+0x2d/0x50 ? kthread_park+0x80/0x80 ret_from_fork_asm+0x11/0x20 </TASK>

How to fix

Remediation Available
linuxDebian
Fixed in:6.11.4-1CVE-2024-49953
Fixed in:6.11.4-1CVE-2024-49953
linuxUbuntu
Fixed in:6.8.0-54.56USN-7301-1
linux-awsUbuntu
Fixed in:6.8.0-1023.25USN-7311-1
linux-aws-6.8Ubuntu
Fixed in:6.8.0-1023.25~22.04.1USN-7311-1
linux-azureUbuntu
Fixed in:6.8.0-1025.30USN-7384-1
linux-azure-6.8Ubuntu
Fixed in:6.8.0-1025.30~22.04.1USN-7384-2
linux-gcpUbuntu
Fixed in:6.8.0-1024.26USN-7304-1
linux-gcp-6.8Ubuntu
Fixed in:6.8.0-1024.26~22.04.1USN-7303-3
linux-gkeUbuntu
Fixed in:6.8.0-1019.23USN-7304-1
linux-gkeopUbuntu
Fixed in:6.8.0-1006.8USN-7304-1
linux-hwe-6.8Ubuntu
Fixed in:6.8.0-57.59~22.04.1USN-7403-1
linux-ibmUbuntu
Fixed in:6.8.0-1022.22USN-7385-1
linux-image-6.11.0-1015-oemUbuntu
Fixed in:6.11.0-1015.15USN-7310-1
linux-image-6.8.0-1006-gkeopUbuntu
Fixed in:6.8.0-1006.8USN-7304-1
linux-image-6.8.0-1019-gkeUbuntu
Fixed in:6.8.0-1019.23USN-7304-1
linux-image-6.8.0-1019-raspiUbuntu
Fixed in:6.8.0-1019.23USN-7303-3
linux-image-6.8.0-1020-oracleUbuntu
Fixed in:6.8.0-1020.21~22.04.1USN-7303-2
Fixed in:6.8.0-1020.21USN-7303-2
linux-image-6.8.0-1020-oracle-64kUbuntu
Fixed in:6.8.0-1020.21~22.04.1USN-7303-2
Fixed in:6.8.0-1020.21USN-7303-2
linux-image-6.8.0-1022-ibmUbuntu
Fixed in:6.8.0-1022.22USN-7385-1
linux-image-6.8.0-1022-nvidiaUbuntu
Fixed in:6.8.0-1022.25~22.04.2USN-7303-1
Fixed in:6.8.0-1022.25USN-7303-1
linux-image-6.8.0-1022-nvidia-64kUbuntu
Fixed in:6.8.0-1022.25~22.04.2USN-7303-1
Fixed in:6.8.0-1022.25USN-7303-1
linux-image-6.8.0-1022-nvidia-lowlatencyUbuntu
Fixed in:6.8.0-1022.25.2USN-7303-1
linux-image-6.8.0-1022-nvidia-lowlatency-64kUbuntu
Fixed in:6.8.0-1022.25.2USN-7303-1
linux-image-6.8.0-1023-awsUbuntu
Fixed in:6.8.0-1023.25~22.04.1USN-7311-1
Fixed in:6.8.0-1023.25USN-7311-1
linux-image-6.8.0-1024-gcpUbuntu
Fixed in:6.8.0-1024.26~22.04.1USN-7303-3
Fixed in:6.8.0-1024.26USN-7304-1
linux-image-6.8.0-1024-gcp-64kUbuntu
Fixed in:6.8.0-1024.26~22.04.1USN-7303-3
Fixed in:6.8.0-1024.26USN-7304-1
linux-image-6.8.0-1024-oemUbuntu
Fixed in:6.8.0-1024.24USN-7386-1
linux-image-6.8.0-1025-azureUbuntu
Fixed in:6.8.0-1025.30~22.04.1USN-7384-2
Fixed in:6.8.0-1025.30USN-7384-1
linux-image-6.8.0-1025-azure-fdeUbuntu
Fixed in:6.8.0-1025.30~22.04.1USN-7384-2
Fixed in:6.8.0-1025.30USN-7384-1
linux-image-6.8.0-54-genericUbuntu
Fixed in:6.8.0-54.56USN-7301-1
linux-image-6.8.0-54-generic-64kUbuntu
Fixed in:6.8.0-54.56USN-7301-1
linux-image-6.8.0-54-lowlatencyUbuntu
Fixed in:6.8.0-54.56.1~22.04.1USN-7301-1
Fixed in:6.8.0-54.56.1USN-7301-1
linux-image-6.8.0-54-lowlatency-64kUbuntu
Fixed in:6.8.0-54.56.1~22.04.1USN-7301-1
Fixed in:6.8.0-54.56.1USN-7301-1
linux-image-6.8.0-57-genericUbuntu
Fixed in:6.8.0-57.59~22.04.1USN-7403-1
linux-image-6.8.0-57-generic-64kUbuntu
Fixed in:6.8.0-57.59~22.04.1USN-7403-1
linux-image-awsUbuntu
Fixed in:6.8.0-1023.25~22.04.1USN-7311-1
Fixed in:6.8.0-1023.25USN-7311-1
linux-image-aws-lts-24.04Ubuntu
Fixed in:6.8.0-1023.25USN-7311-1
linux-image-azureUbuntu
Fixed in:6.8.0-1025.30~22.04.1USN-7384-2
linux-image-azure-fdeUbuntu
Fixed in:6.8.0-1025.30~22.04.1USN-7384-2
linux-image-azure-fde-lts-24.04Ubuntu
Fixed in:6.8.0-1025.30USN-7384-1
linux-image-azure-lts-24.04Ubuntu
Fixed in:6.8.0-1025.30USN-7384-1
linux-image-gcpUbuntu
Fixed in:6.8.0-1024.26~22.04.1USN-7303-3
Fixed in:6.8.0-1024.26USN-7304-1
linux-image-gcp-64kUbuntu
Fixed in:6.8.0-1024.26~22.04.1USN-7303-3
Fixed in:6.8.0-1024.26USN-7304-1
linux-image-gcp-64k-lts-24.04Ubuntu
Fixed in:6.8.0-1024.26USN-7304-1
linux-image-gcp-lts-24.04Ubuntu
Fixed in:6.8.0-1024.26USN-7304-1
linux-image-genericUbuntu
Fixed in:6.8.0-54.56USN-7301-1
linux-image-generic-64kUbuntu
Fixed in:6.8.0-54.56USN-7301-1
linux-image-generic-64k-hwe-22.04Ubuntu
Fixed in:6.8.0-57.59~22.04.1USN-7403-1
linux-image-generic-hwe-22.04Ubuntu
Fixed in:6.8.0-57.59~22.04.1USN-7403-1
linux-image-generic-lpaeUbuntu
Fixed in:6.8.0-54.56USN-7301-1
linux-image-gkeUbuntu
Fixed in:6.8.0-1019.23USN-7304-1
linux-image-gkeopUbuntu
Fixed in:6.8.0-1006.8USN-7304-1
linux-image-gkeop-6.8Ubuntu
Fixed in:6.8.0-1006.8USN-7304-1
linux-image-ibmUbuntu
Fixed in:6.8.0-1022.22USN-7385-1
linux-image-ibm-classicUbuntu
Fixed in:6.8.0-1022.22USN-7385-1
linux-image-ibm-lts-24.04Ubuntu
Fixed in:6.8.0-1022.22USN-7385-1
linux-image-kvmUbuntu
Fixed in:6.8.0-54.56USN-7301-1
linux-image-lowlatencyUbuntu
Fixed in:6.8.0-54.56.1USN-7301-1
linux-image-lowlatency-64kUbuntu
Fixed in:6.8.0-54.56.1USN-7301-1
linux-image-lowlatency-64k-hwe-22.04Ubuntu
Fixed in:6.8.0-54.56.1~22.04.1USN-7301-1
linux-image-lowlatency-hwe-22.04Ubuntu
Fixed in:6.8.0-54.56.1~22.04.1USN-7301-1
linux-image-nvidiaUbuntu
Fixed in:6.8.0-1022.25USN-7303-1
linux-image-nvidia-6.8Ubuntu
Fixed in:6.8.0-1022.25~22.04.2USN-7303-1
linux-image-nvidia-64kUbuntu
Fixed in:6.8.0-1022.25USN-7303-1
linux-image-nvidia-64k-6.8Ubuntu
Fixed in:6.8.0-1022.25~22.04.2USN-7303-1
linux-image-nvidia-64k-hwe-22.04Ubuntu
Fixed in:6.8.0-1022.25~22.04.2USN-7303-1
linux-image-nvidia-hwe-22.04Ubuntu
Fixed in:6.8.0-1022.25~22.04.2USN-7303-1
linux-image-nvidia-lowlatencyUbuntu
Fixed in:6.8.0-1022.25.2USN-7303-1
linux-image-nvidia-lowlatency-64kUbuntu
Fixed in:6.8.0-1022.25.2USN-7303-1
linux-image-oem-22.04Ubuntu
Fixed in:6.8.0-57.59~22.04.1USN-7403-1
linux-image-oem-22.04aUbuntu
Fixed in:6.8.0-57.59~22.04.1USN-7403-1
linux-image-oem-22.04bUbuntu
Fixed in:6.8.0-57.59~22.04.1USN-7403-1
linux-image-oem-22.04cUbuntu
Fixed in:6.8.0-57.59~22.04.1USN-7403-1
linux-image-oem-22.04dUbuntu
Fixed in:6.8.0-57.59~22.04.1USN-7403-1
linux-image-oem-24.04Ubuntu
Fixed in:6.8.0-1024.24USN-7386-1
linux-image-oem-24.04aUbuntu
Fixed in:6.8.0-1024.24USN-7386-1
linux-image-oem-24.04bUbuntu
Fixed in:6.11.0-1015.15USN-7310-1
linux-image-oracleUbuntu
Fixed in:6.8.0-1020.21~22.04.1USN-7303-2
Fixed in:6.8.0-1020.21USN-7303-2
linux-image-oracle-64kUbuntu
Fixed in:6.8.0-1020.21~22.04.1USN-7303-2
Fixed in:6.8.0-1020.21USN-7303-2
linux-image-oracle-64k-lts-24.04Ubuntu
Fixed in:6.8.0-1020.21USN-7303-2
linux-image-oracle-lts-24.04Ubuntu
Fixed in:6.8.0-1020.21USN-7303-2
linux-image-raspiUbuntu
Fixed in:6.8.0-1019.23USN-7303-3
linux-image-virtualUbuntu
Fixed in:6.8.0-54.56USN-7301-1
linux-image-virtual-hwe-22.04Ubuntu
Fixed in:6.8.0-57.59~22.04.1USN-7403-1
linux-lowlatencyUbuntu
Fixed in:6.8.0-54.56.1USN-7301-1
linux-lowlatency-hwe-6.8Ubuntu
Fixed in:6.8.0-54.56.1~22.04.1USN-7301-1
linux-nvidiaUbuntu
Fixed in:6.8.0-1022.25USN-7303-1
linux-nvidia-6.8Ubuntu
Fixed in:6.8.0-1022.25~22.04.2USN-7303-1
linux-nvidia-lowlatencyUbuntu
Fixed in:6.8.0-1022.25.2USN-7303-1
linux-oem-6.11Ubuntu
Fixed in:6.11.0-1015.15USN-7310-1
linux-oem-6.8Ubuntu
Fixed in:6.8.0-1024.24USN-7386-1
linux-oracleUbuntu
Fixed in:6.8.0-1020.21USN-7303-2
linux-oracle-6.8Ubuntu
Fixed in:6.8.0-1020.21~22.04.1USN-7303-2
linux-raspiUbuntu
Fixed in:6.8.0-1019.23USN-7303-3

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityNone
IntegrityNone
AvailabilityHigh

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Exploit Intelligence

0.30%probability of exploitation in 30 days
22ndpercentile

Low risk: more likely to be exploited than 22% of all known CVEs.

References

Embed a live status badge for CVE-2024-49953
CVE-2024-49953 severity badge

Markdown

[![CVE-2024-49953](https://tridentstack.com/cve/badge/CVE-2024-49953.svg)](https://tridentstack.com/cve/CVE-2024-49953)

HTML

<a href="https://tridentstack.com/cve/CVE-2024-49953"><img src="https://tridentstack.com/cve/badge/CVE-2024-49953.svg" alt="CVE-2024-49953"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-07.