{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-44998","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-08-21T05:34:56.672Z","datePublished":"2024-09-04T19:54:42.826Z","dateUpdated":"2026-08-05T11:37:36.271Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:37:36.271Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\natm: idt77252: prevent use after free in dequeue_rx()\n\nWe can't dereference \"skb\" after calling vcc->push() because the skb\nis released."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The UAF is triggered purely by an AAL5 PDU received from the remote end of an ATM virtual circuit, processed in the card's interrupt handler before any higher-layer filtering. ATM VCs are switched WAN circuits (DSL/backhaul), and via br2684/pppoatm they carry ordinary internet traffic, so the attacker set extends beyond a single shared segment.\nAC:L - The attacker fully controls both the packet size (choosing the single-skb reassembly branch) and the encapsulation header that forces br2684_push()/pppoatm_push() down their `kfree_skb()` error path, making the use-after-free deterministic on a single packet with no race to win.\nPR:N - No authentication or authorization exists anywhere on this path — the skb is freed and then re-dereferenced inside the driver's hardirq receive handler, long before any application-level credential check.\nUI:N - The vulnerable code runs automatically on packet reception; no local user must open, mount, or interact with anything for the attacker's frame to be processed.\nS:U - The freed sk_buff and the corrupted buffer-management state are both kernel resources managed by the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is a use-after-free read of a slab object the attacker can groom by keeping concurrent traffic in flight, so the reclaimed sk_buff contents are read back into driver control flow — per kernel UAF convention this constitutes a high-confidentiality read primitive.\nI:H - A use-after-free on a sprayable slab object allows the attacker to influence the value the driver consumes, which in turn drives subsequent skb allocation, DMA mapping, and free-buffer-queue bookkeeping; UAFs of this class are treated as exploitable for arbitrary write/control-flow hijacking.\nA:H - The stale read occurs in hardirq context and panics KASAN/KFENCE/panic_on_warn kernels; even on stock kernels, repeated remote packets cause the wrong free-buffer queue to be refilled, starving the correct SAR FBQ and permanently stalling the card's receive path."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/atm/idt77252.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"628ea82190a678a56d2ec38cda3addf3b3a6248d","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"09e086a5f72ea27c758b3f3b419a69000c32adc1","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1cece837e387c039225f19028df255df87a97c0d","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"24cf390a5426aac9255205e9533cdd7b4235d518","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"379a6a326514a3e2f71b674091dfb0e0e7522b55","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ef23c18ab88e33ce000d06a5c6aad0620f219bfd","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"91b4850e7165a4b7180ef1e227733bcb41ccdf10","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a9a18e8f770c9b0703dab93580d0b02e199a4c79","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/atm/idt77252.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"4.19.321","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.283","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.225","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.166","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.107","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.48","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.10.7","lessThanOrEqual":"6.10.*","status":"unaffected","versionType":"semver"},{"version":"6.11","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"4.19.321"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.4.283"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.10.225"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.15.166"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.107"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.48"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.10.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.11"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/628ea82190a678a56d2ec38cda3addf3b3a6248d"},{"url":"https://git.kernel.org/stable/c/09e086a5f72ea27c758b3f3b419a69000c32adc1"},{"url":"https://git.kernel.org/stable/c/1cece837e387c039225f19028df255df87a97c0d"},{"url":"https://git.kernel.org/stable/c/24cf390a5426aac9255205e9533cdd7b4235d518"},{"url":"https://git.kernel.org/stable/c/379a6a326514a3e2f71b674091dfb0e0e7522b55"},{"url":"https://git.kernel.org/stable/c/ef23c18ab88e33ce000d06a5c6aad0620f219bfd"},{"url":"https://git.kernel.org/stable/c/91b4850e7165a4b7180ef1e227733bcb41ccdf10"},{"url":"https://git.kernel.org/stable/c/a9a18e8f770c9b0703dab93580d0b02e199a4c79"}],"title":"atm: idt77252: prevent use after free in dequeue_rx()","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-04T20:19:05.283493Z","id":"CVE-2024-44998","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-04T20:19:17.632Z"}},{"title":"CVE Program Container","references":[{"url":"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"},{"url":"https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-03T22:14:54.152Z"}}]}}