Executive Summary

Informations
Name CVE-2024-53138 First vendor Publication 2024-12-04
Vendor Cve Last vendor Modification 2024-12-14

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.6 Temporal Score 5.5
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: kTLS, Fix incorrect page refcounting

The kTLS tx handling code is using a mix of get_page() and page_ref_inc() APIs to increment the page reference. But on the release path (mlx5e_ktls_tx_handle_resync_dump_comp()), only put_page() is used.

This is an issue when using pages from large folios: the get_page() references are stored on the folio page while the page_ref_inc() references are stored directly in the given page. On release the folio page will be dereferenced too many times.

This was found while doing kTLS testing with sendfile() + ZC when the served file was read from NFS on a kernel with NFS large folios support (commit 49b29a573da8 ("nfs: add support for large folios")).

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-53138

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3689

Sources (Detail)

https://git.kernel.org/stable/c/2723e8b2cbd486cb96e5a61b22473f7fd62e18df
https://git.kernel.org/stable/c/69fbd07f17b0fdaf8970bc705f5bf115c297839d
https://git.kernel.org/stable/c/93a14620b97c911489a5b008782f3d9b0c4aeff4
https://git.kernel.org/stable/c/a0ddb20a748b122ea86003485f7992fa5e84cc95
https://git.kernel.org/stable/c/c7b97f9e794d8e2bbaa50e1d6c230196fd214b5e
https://git.kernel.org/stable/c/dd6e972cc5890d91d6749bb48e3912721c4e4b25
https://git.kernel.org/stable/c/ffad2ac8c859c1c1a981fe9c4f7ff925db684a43
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
Date Informations
2025-03-29 03:43:43
  • Multiple Updates
2025-03-28 13:47:11
  • Multiple Updates
2025-03-28 03:21:29
  • Multiple Updates
2025-03-19 03:16:32
  • Multiple Updates
2025-03-18 03:29:31
  • Multiple Updates
2025-03-14 03:16:41
  • Multiple Updates
2025-03-06 14:13:13
  • Multiple Updates
2025-02-22 03:26:46
  • Multiple Updates
2025-01-08 03:07:37
  • Multiple Updates
2025-01-07 03:07:11
  • Multiple Updates
2024-12-25 03:05:46
  • Multiple Updates
2024-12-15 00:20:30
  • Multiple Updates
2024-12-12 00:20:30
  • Multiple Updates
2024-12-11 21:20:31
  • Multiple Updates
2024-12-04 21:20:29
  • First insertion