In the Linux kernel, the following vulnerability has been resolved:
mm: list_lru: fix UAF for memory cgroup
The mem_cgroup_from_slab_obj() is supposed to be called under rcu lock or
cgroup_mutex or others which could prevent returned memcg from being
freed. Fix it by adding missing rcu read lock.
Found by code inspection.
[[email protected]: only grab rcu lock when necessary, per Vlastimil]
CVE ID: CVE-2024-43888
CVSS Base Severity: HIGH
CVSS Base Score: 7.8
Vendor: Linux
Product: Linux, Linux
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.04% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false