CVE Database
/

CVE-2024-50080

Back to search

CVE-2024-50080

Published: Oct 29, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: ublk: don't allow user copy for unprivileged device UBLK_F_USER_COPY requires userspace to call write() on ublk char device for filling request buffer, and unprivileged device can't be trusted. So don't allow user copy for unprivileged device.

VendorProductVersions

Linux

Linux

affected
1172d5b8beca6b899deb9f7f2850e7e47ec16198 - < 6414ab5c9c9c068eca6dc4fd3a036bc4b83164dc
affected
1172d5b8beca6b899deb9f7f2850e7e47ec16198 - < 8f3d5686a2409877c5e8e2540774d24ed2b4a4ce
affected
1172d5b8beca6b899deb9f7f2850e7e47ec16198 - < 42aafd8b48adac1c3b20fe5892b1b91b80c1a1e6

Linux

Linux

affected
6.5
unaffected
0 - < 6.5
unaffected
6.6.58 - <= 6.6.*
unaffected
6.11.5 - <= 6.11.*
unaffected
6.12 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now