THREATOPS
THREAT OPSThreat News › [NVD] CVE-2024-26625 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: llc: call sock_orphan() at release time syzbot reported an interesting trace [1] caused by a stale sk->sk_wq pointer in a closed llc socket. In commit ff7b11aa481f ("net: socket: set sock->sk to NULL after cal

[NVD] CVE-2024-26625 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: llc: call sock_orphan() at release time syzbot reported an interesting trace [1] caused by a stale sk->sk_wq pointer in a closed llc socket. In commit ff7b11aa481f ("net: socket: set sock->sk to NULL after cal

lownvdPublished 2024-03-06

CVE-2024-26625 CVSS: 7.8 HIGH Published: 2024-03-06T07:15:12.587

In the Linux kernel, the following vulnerability has been resolved:

llc: call sock_orphan() at release time

syzbot reported an interesting trace [1] caused by a stale sk->sk_wq pointer in a closed llc socket.

In commit ff7b11aa481f ("net: socket: set sock->sk to NULL after calling proto_ops::release()") Eric Biggers hinted that s

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-26625