Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-53103— hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于hv_sock组件中vsk->trans指针在hvs释放后可能未初始化为NULL,导致悬挂指针问题。

CVSS 7.8 · High EPSS 0.24% · P15

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux ae0078fcf0a5eb3a8623bfb5f988262e0911fdb9< 285266ef92f7b4bf7d26e1e95e215ce6a6badb4a affected
ae0078fcf0a5eb3a8623bfb5f988262e0911fdb9< 4fe1d42f2acc463b733bb42e3f8e67dbc2a0eb2d affected
ae0078fcf0a5eb3a8623bfb5f988262e0911fdb9< 414476c4fb11be070c09ab8f3e75c9ee324a108a affected
ae0078fcf0a5eb3a8623bfb5f988262e0911fdb9< 7cf25987820350cb950856c71b409e5b6eed52bd affected
ae0078fcf0a5eb3a8623bfb5f988262e0911fdb9< 98d8dde9232250a57ad5ef16479bf6a349e09b80 affected
ae0078fcf0a5eb3a8623bfb5f988262e0911fdb9< 4bdc5a62c6e50600d8a1c3e18fd6dce0c27c9497 affected
ae0078fcf0a5eb3a8623bfb5f988262e0911fdb9< e0fe3392371293175f25028020ded5267f4cd8e3 affected
ae0078fcf0a5eb3a8623bfb5f988262e0911fdb9< 8621725afb38e111969c64280b71480afde2aace affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-53103

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer When hvs is released, there is a possibility that vsk->trans may not be initialized to NULL, which could lead to a dangling pointer. This issue is resolved by initializing vsk->trans to NULL.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于hv_sock组件中vsk->trans指针在hvs释放后可能未初始化为NULL,导致悬挂指针问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux ae0078fcf0a5eb3a8623bfb5f988262e0911fdb9 ~ 285266ef92f7b4bf7d26e1e95e215ce6a6badb4a -
Linux Linux 4.14 -

II. Public POCs for CVE-2024-53103

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-53103

登录查看更多情报信息。

Patches & Fixes for CVE-2024-53103 (9)

Same Patch Batch · Linux · 2024-12-02 · 22 CVEs total

CVE-2024-53121 7.8 HIGH net/mlx5: fs, lock FTE when checking if active
CVE-2024-53107 7.8 HIGH fs/proc/task_mmu: prevent integer overflow in pagemap_scan_get_args()
CVE-2024-53109 7.8 HIGH nommu: pass NULL argument to vma_iter_prealloc()
CVE-2024-53122 7.5 HIGH mptcp: cope racing subflow creation in mptcp_rcv_space_adjust
CVE-2024-53120 7.5 HIGH net/mlx5e: CT: Fix null-ptr-deref in add rule err flow
CVE-2024-53124 7.5 HIGH net: fix data-races around sk->sk_forward_alloc
CVE-2024-53106 7.3 HIGH ima: fix buffer overrun in ima_eventdigest_init_common
CVE-2024-53108 7.3 HIGH drm/amd/display: Adjust VSDB parser for replay feature
CVE-2024-53110 7.3 HIGH vp_vdpa: fix id_table array not null terminated error
CVE-2024-53111 7.1 HIGH mm/mremap: fix address wraparound in move_page_tables()
CVE-2024-53114 x86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client
CVE-2024-53104 media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
CVE-2024-53105 mm: page_alloc: move mlocked flag clearance into free_pages_prepare()
CVE-2024-53112 ocfs2: uncache inode which has failed entering the group
CVE-2024-53113 mm: fix NULL pointer dereference in alloc_pages_bulk_noprof
CVE-2024-53115 drm/vmwgfx: avoid null_ptr_deref in vmw_framebuffer_surface_create_handle
CVE-2024-53116 drm/panthor: Fix handling of partial GPU mapping of BOs
CVE-2024-53117 virtio/vsock: Improve MSG_ZEROCOPY error handling
CVE-2024-53119 virtio/vsock: Fix accept_queue memory leak
CVE-2024-53118 vsock: Fix sk_error_queue memory leak

Showing top 20 of 22 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-53103

No comments yet


Leave a comment