{"id":"DEBIAN-CVE-2024-53184","details":"In the Linux kernel, the following vulnerability has been resolved:  um: ubd: Do not use drvdata in release  The drvdata is not available in release. Let's just use container_of() to get the ubd instance. Otherwise, removing a ubd device will result in a crash:  RIP: 0033:blk_mq_free_tag_set+0x1f/0xba RSP: 00000000e2083bf0  EFLAGS: 00010246 RAX: 000000006021463a RBX: 0000000000000348 RCX: 0000000062604d00 RDX: 0000000004208060 RSI: 00000000605241a0 RDI: 0000000000000348 RBP: 00000000e2083c10 R08: 0000000062414010 R09: 00000000601603f7 R10: 000000000000133a R11: 000000006038c4bd R12: 0000000000000000 R13: 0000000060213a5c R14: 0000000062405d20 R15: 00000000604f7aa0 Kernel panic - not syncing: Segfault with no mm CPU: 0 PID: 17 Comm: kworker/0:1 Not tainted 6.8.0-rc3-00107-gba3f67c11638 #1 Workqueue: events mc_work_proc Stack:  00000000 604f7ef0 62c5d000 62405d20  e2083c30 6002c776 6002c755 600e47ff  e2083c60 6025ffe3 04208060 603d36e0 Call Trace:  [\u003c6002c776\u003e] ubd_device_release+0x21/0x55  [\u003c6002c755\u003e] ? ubd_device_release+0x0/0x55  [\u003c600e47ff\u003e] ? kfree+0x0/0x100  [\u003c6025ffe3\u003e] device_release+0x70/0xba  [\u003c60381d6a\u003e] kobject_put+0xb5/0xe2  [\u003c6026027b\u003e] put_device+0x19/0x1c  [\u003c6026a036\u003e] platform_device_put+0x26/0x29  [\u003c6026ac5a\u003e] platform_device_unregister+0x2c/0x2e  [\u003c6002c52e\u003e] ubd_remove+0xb8/0xd6  [\u003c6002bb74\u003e] ? mconsole_reply+0x0/0x50  [\u003c6002b926\u003e] mconsole_remove+0x160/0x1cc  [\u003c6002bbbc\u003e] ? mconsole_reply+0x48/0x50  [\u003c6003379c\u003e] ? um_set_signals+0x3b/0x43  [\u003c60061c55\u003e] ? update_min_vruntime+0x14/0x70  [\u003c6006251f\u003e] ? dequeue_task_fair+0x164/0x235  [\u003c600620aa\u003e] ? update_cfs_group+0x0/0x40  [\u003c603a0e77\u003e] ? __schedule+0x0/0x3ed  [\u003c60033761\u003e] ? um_set_signals+0x0/0x43  [\u003c6002af6a\u003e] mc_work_proc+0x77/0x91  [\u003c600520b4\u003e] process_scheduled_works+0x1af/0x2c3  [\u003c6004ede3\u003e] ? assign_work+0x0/0x58  [\u003c600527a1\u003e] worker_thread+0x2f7/0x37a  [\u003c6004ee3b\u003e] ? set_pf_worker+0x0/0x64  [\u003c6005765d\u003e] ? arch_local_irq_save+0x0/0x2d  [\u003c60058e07\u003e] ? kthread_exit+0x0/0x3a  [\u003c600524aa\u003e] ? worker_thread+0x0/0x37a  [\u003c60058f9f\u003e] kthread+0x130/0x135  [\u003c6002068e\u003e] new_thread_handler+0x85/0xb6","modified":"2026-09-15T09:03:16.283945409Z","published":"2024-12-27T14:15:25.853Z","upstream":["CVE-2024-53184"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-53184"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.123-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-53184.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-53184.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-53184.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}