We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-47750

RDMA/hns: Fix Use-After-Free of rsv_qp on HIP08



AssignerLinux
Reserved2024-09-30
Published2024-10-21
Updated2024-11-05

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix Use-After-Free of rsv_qp on HIP08 Currently rsv_qp is freed before ib_unregister_device() is called on HIP08. During the time interval, users can still dereg MR and rsv_qp will be used in this process, leading to a UAF. Move the release of rsv_qp after calling ib_unregister_device() to fix it.

Product status

Default status
unaffected

70f92521584f before 2ccf1c75d399
affected

70f92521584f before d2d9c5127122
affected

70f92521584f before dac2723d8bfa
affected

70f92521584f before 60595923371c
affected

70f92521584f before fd8489294dd2
affected

Default status
affected

5.18
affected

Any version before 5.18
unaffected

6.1.113
unaffected

6.6.54
unaffected

6.10.13
unaffected

6.11.2
unaffected

6.12-rc1
unaffected

References

https://git.kernel.org/stable/c/2ccf1c75d39949d8ea043d04a2e92d7100ea723d

https://git.kernel.org/stable/c/d2d9c5127122745da6e887f451dd248cfeffca33

https://git.kernel.org/stable/c/dac2723d8bfa9cf5333f477741e6e5fa1ed34645

https://git.kernel.org/stable/c/60595923371c2ebe7faf82536c47eb0c967e3425

https://git.kernel.org/stable/c/fd8489294dd2beefb70f12ec4f6132aeec61a4d0

cve.org CVE-2024-47750

nvd.nist.gov CVE-2024-47750

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.