VYPR
High severity7.8NVD Advisory· Published May 19, 2024· Updated Aug 4, 2026

CVE-2024-35874

CVE-2024-35874

Description

In the Linux kernel, the following vulnerability has been resolved:

aio: Fix null ptr deref in aio_complete() wakeup

list_del_init_careful() needs to be the last access to the wait queue entry - it effectively unlocks access.

Previously, finish_wait() would see the empty list head and skip taking the lock, and then we'd return - but the completion path would still attempt to do the wakeup after the task_struct pointer had been overwritten.

Affected products

6
  • Linux/Kernelcpe-rescue5 versions
    6.8+ 4 more
    • (no CPE)range: 6.8
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.8,<6.8.5
    • cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
    • (no CPE)
  • osv-coords
    Range: >= 6.8.0, < 6.8.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.