CVE-2024-50264
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans During loopback communication, a dangling pointer can be created in vsk->trans, potentially leading to a Use-After-Free condition. This issue is resolved by initializing vsk->trans to NULL.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Debian, Linuxmint, Linux Kernel, Red Hat
- Linux Linux Kernel
- < 4.19.324, 5.4.286, 5.10.230, 5.15.172, 6.1.117, 6.6.61, 6.11.8, 6.12
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.4% (28th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2024-11-19
CVE-2024-50264 at NVD
1 known exploit for CVE-2024-50264
Proof-of-concept code and exploit modules indexed by Sploitus