CVE-2024-53170

HIGHNVD 7.87.8
EchelonGraph scoreMEDIUM confidence

Score 7.8 from GitHub Security Advisory (severity: HIGH) published 2024-12-27. NVD baseline CVSS 7.8; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, nvd
7.8
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS: 0%CVSS: 7.8Exploit: NoneExposed: 0

A fix is available — apply it.

In the Linux kernel, the following vulnerability has been resolved:

block: fix uaf for flush rq while iterating tags

blk_mq_clear_flush_rq_mapping() is not called during scsi probe, by checking blk_queue_init_done(). However, QUEUE_FLAG_INIT_DONE is cleared in del_gendisk by commit aec89dc5d421 ("block: keep q_usage_counter in atomic mode after del_gendisk"), hence for disk like scsi, following blk_mq_destroy_queue() will not clear flush rq from tags->rqs[] as well, cause following uaf that is found by our syzkaller for v6.6:

================================================================== BUG: KASAN: slab-use-after-free in blk_mq_find_and_get_req+0x16e/0x1a0 block/blk-mq-tag.c:261 Read of size 4 at addr ffff88811c969c20 by task kworker/1:2H/224909

CPU: 1 PID: 224909 Comm: kworker/1:2H Not tainted 6.6.0-ga836a5060850 #32 Workqueue: kblockd blk_mq_timeout_work Call Trace:

__dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x91/0xf0 lib/dump_stack.c:106 print_address_description.constprop.0+0x66/0x300 mm/kasan/report.c:364 print_report+0x3e/0x70 mm/kasan/report.c:475 kasan_report+0xb8/0xf0 mm/kasan/report.c:588 blk_mq_find_and_get_req+0x16e/0x1a0 block/blk-mq-tag.c:261 bt_iter block/blk-mq-tag.c:288 [inline] __sbitmap_for_each_set include/linux/sbitmap.h:295 [inline] sbitmap_for_each_set include/linux/sbitmap.h:316 [inline] bt_for_each+0x455/0x790 block/blk-mq-tag.c:325 blk_mq_queue_tag_busy_iter+0x320/0x740 block/blk-mq-tag.c:534 blk_mq_timeout_work+0x1a3/0x7b0 block/blk-mq.c:1673 process_one_work+0x7c4/0x1450 kernel/workqueue.c:2631 process_scheduled_works kernel/workqueue.c:2704 [inline] worker_thread+0x804/0xe40 kernel/workqueue.c:2785 kthread+0x346/0x450 kernel/kthread.c:388 ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1b/0x30 arch/x86/entry/entry_64.S:293

Allocated by task 942: kasan_save_stack+0x22/0x50 mm/kasan/common.c:45 kasan_set_track+0x25/0x30 mm/kasan/common.c:52 ____kasan_kmalloc mm/kasan/common.c:374 [inline] __kasan_kmalloc mm/kasan/common.c:383 [inline] __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:380 kasan_kmalloc include/linux/kasan.h:198 [inline] __do_kmalloc_node mm/slab_common.c:1007 [inline] __kmalloc_node+0x69/0x170 mm/slab_common.c:1014 kmalloc_node include/linux/slab.h:620 [inline] kzalloc_node include/linux/slab.h:732 [inline] blk_alloc_flush_queue+0x144/0x2f0 block/blk-flush.c:499 blk_mq_alloc_hctx+0x601/0x940 block/blk-mq.c:3788 blk_mq_alloc_and_init_hctx+0x27f/0x330 block/blk-mq.c:4261 blk_mq_realloc_hw_ctxs+0x488/0x5e0 block/blk-mq.c:4294 blk_mq_init_allocated_queue+0x188/0x860 block/blk-mq.c:4350 blk_mq_init_queue_data block/blk-mq.c:4166 [inline] blk_mq_init_queue+0x8d/0x100 block/blk-mq.c:4176 scsi_alloc_sdev+0x843/0xd50 drivers/scsi/scsi_scan.c:335 scsi_probe_and_add_lun+0x77c/0xde0 drivers/scsi/scsi_scan.c:1189 __scsi_scan_target+0x1fc/0x5a0 drivers/scsi/scsi_scan.c:1727 scsi_scan_channel drivers/scsi/scsi_scan.c:1815 [inline] scsi_scan_channel+0x14b/0x1e0 drivers/scsi/scsi_scan.c:1791 scsi_scan_host_selected+0x2fe/0x400 drivers/scsi/scsi_scan.c:1844 scsi_scan+0x3a0/0x3f0 drivers/scsi/scsi_sysfs.c:151 store_scan+0x2a/0x60 drivers/scsi/scsi_sysfs.c:191 dev_attr_store+0x5c/0x90 drivers/base/core.c:2388 sysfs_kf_write+0x11c/0x170 fs/sysfs/file.c:136 kernfs_fop_write_iter+0x3fc/0x610 fs/kernfs/file.c:338 call_write_iter include/linux/fs.h:2083 [inline] new_sync_write+0x1b4/0x2d0 fs/read_write.c:493 vfs_write+0x76c/0xb00 fs/read_write.c:586 ksys_write+0x127/0x250 fs/read_write.c:639 do_syscall_x64 arch/x86/entry/common.c:51 [inline] do_syscall_64+0x70/0x120 arch/x86/entry/common.c:81 entry_SYSCALL_64_after_hwframe+0x78/0xe2

Freed by task 244687: kasan_save_stack+0x22/0x50 mm/kasan/common.c:45 kasan_set_track+0x25/0x30 mm/kasan/common.c:52 kasan_save_free_info+0x2b/0x50 mm/kasan/generic.c:522 ____kasan_slab_free mm/kasan/common.c:236 [inline] __kasan_slab_free+0x12a/0x1b0 mm/kasan/common.c:244 kasan_slab_free include/linux/kasan.h:164 [in ---truncated---

CVSS v3
7.8
EG Score
7.8(medium)
EG Risk
EPSS
15.2%
KEV
Not listed

Published

December 27, 2024

Last Modified

July 14, 2026

Advisory Details (7)

Auto-updated Jul 14, 2026
Patch available.
generic Patch Available

[SECURITY] [DLA 4076-1] linux-6.1 security update

https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
generic

block: fix uaf for flush rq while iterating tags - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/a0e93b9fefafe97d596f9c98701ae6c3b04b3ff6
generic

block: fix uaf for flush rq while iterating tags - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/61092568f2a9acb0e6e186f03f2e0649a4e86d09
generic

block: fix uaf for flush rq while iterating tags - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/3802f73bd80766d70f319658f334754164075bc3
generic

block: fix uaf for flush rq while iterating tags - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/1921fe7d2836f8be1d321cf430d17e0d4e05301b
generic

block: fix uaf for flush rq while iterating tags - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/1364a29b71c7837770f1902c49e7a6e234d72c92

Vendor Advisories for CVE-2024-53170(2)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Patch Availability(16)

Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Additional Vendor Advisories

(15)

Data Freshness Timeline

(refreshed 9× in last 7d / 41× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-07-22 14:07 UTCEPSS rescore
  2. 2026-07-21 15:23 UTCEPSS rescore
  3. 2026-07-20 17:07 UTCEPSS rescore
  4. 2026-07-19 14:30 UTCEPSS rescore
  5. 2026-07-19 14:30 UTCEPSS rescore
  6. 2026-07-19 02:28 UTCEPSS rescore
  7. 2026-07-19 02:28 UTCEPSS rescore
  8. 2026-07-18 10:03 UTCEPSS rescore
  9. 2026-07-16 17:02 UTCEPSS rescore
  10. 2026-07-15 16:57 UTCEPSS rescore
  11. 2026-07-15 01:59 UTCEPSS rescore
  12. 2026-07-15 01:59 UTCEPSS rescore
  13. 2026-07-13 22:29 UTCEPSS rescore
  14. 2026-07-13 16:07 UTCOSV refresh
  15. 2026-07-13 06:12 UTCEPSS rescore
  16. 2026-07-12 05:45 UTCEPSS rescore
  17. 2026-07-11 08:26 UTCEPSS rescore
  18. 2026-07-09 19:09 UTCEPSS rescore
  19. 2026-07-09 19:09 UTCEPSS rescore
  20. 2026-07-08 15:14 UTCEPSS rescore
  21. 2026-07-07 13:45 UTCEPSS rescore
  22. 2026-07-07 13:45 UTCEPSS rescore
  23. 2026-07-06 16:26 UTCEPSS rescore
  24. 2026-07-06 16:26 UTCEPSS rescore
  25. 2026-07-06 02:22 UTCEPSS rescore
Show 64 more
  1. 2026-07-05 02:29 UTCEPSS rescore
  2. 2026-07-01 15:06 UTCEPSS rescore
  3. 2026-06-30 23:21 UTCEPSS rescore
  4. 2026-06-30 23:21 UTCEPSS rescore
  5. 2026-06-29 14:05 UTCEPSS rescore
  6. 2026-06-28 14:07 UTCEPSS rescore
  7. 2026-06-28 04:55 UTCEPSS rescore
  8. 2026-06-28 04:55 UTCEPSS rescore
  9. 2026-06-27 03:08 UTCEPSS rescore
  10. 2026-06-27 03:07 UTCEPSS rescore
  11. 2026-06-25 13:49 UTCEPSS rescore
  12. 2026-06-25 13:49 UTCEPSS rescore
  13. 2026-06-25 13:31 UTCOSV refresh
  14. 2026-06-24 14:04 UTCEPSS rescore
  15. 2026-06-24 14:04 UTCEPSS rescore
  16. 2026-06-23 21:32 UTCEPSS rescore
  17. 2026-06-22 14:25 UTCEPSS rescore
  18. 2026-06-22 14:25 UTCEPSS rescore
  19. 2026-06-21 14:56 UTCEPSS rescore
  20. 2026-06-21 14:56 UTCEPSS rescore
  21. 2026-06-21 01:59 UTCEPSS rescore
  22. 2026-06-19 19:25 UTCEPSS rescore
  23. 2026-06-19 19:25 UTCEPSS rescore
  24. 2026-06-18 17:52 UTCEPSS rescore
  25. 2026-06-18 17:52 UTCEPSS rescore
  26. 2026-06-17 17:52 UTCEPSS rescore
  27. 2026-06-16 17:52 UTCEPSS rescore
  28. 2026-06-15 17:48 UTCEPSS rescore
  29. 2026-06-14 23:17 UTCEPSS rescore
  30. 2026-06-13 22:59 UTCEPSS rescore
  31. 2026-06-13 22:59 UTCEPSS rescore
  32. 2026-06-12 23:11 UTCEPSS rescore
  33. 2026-06-12 23:11 UTCEPSS rescore
  34. 2026-06-11 13:59 UTCEPSS rescore
  35. 2026-06-11 13:59 UTCEPSS rescore
  36. 2026-06-10 22:18 UTCEPSS rescore
  37. 2026-06-10 13:21 UTCEPSS rescore
  38. 2026-06-08 14:16 UTCEPSS rescore
  39. 2026-06-08 14:16 UTCEPSS rescore
  40. 2026-06-08 03:58 UTCOSV refresh
  41. 2026-06-05 22:46 UTCEPSS rescore
  42. 2026-06-05 22:46 UTCEPSS rescore
  43. 2026-06-05 06:09 UTCEPSS rescore
  44. 2026-06-05 06:09 UTCEPSS rescore
  45. 2026-06-04 13:11 UTCEPSS rescore
  46. 2026-06-04 13:11 UTCEPSS rescore
  47. 2026-06-02 20:12 UTCEPSS rescore
  48. 2026-06-01 13:51 UTCEPSS rescore
  49. 2026-06-01 13:51 UTCEPSS rescore
  50. 2026-05-31 22:30 UTCEPSS rescore
  51. 2026-05-31 22:30 UTCEPSS rescore
  52. 2026-05-31 00:16 UTCEPSS rescore
  53. 2026-05-31 00:16 UTCEPSS rescore
  54. 2026-05-29 13:43 UTCEPSS rescore
  55. 2026-05-28 13:44 UTCEPSS rescore
  56. 2026-05-28 13:44 UTCEPSS rescore
  57. 2026-05-28 13:44 UTCEPSS rescore
  58. 2026-05-27 13:40 UTCEPSS rescore
  59. 2026-05-27 13:40 UTCEPSS rescore
  60. 2026-05-26 13:43 UTCEPSS rescore
  61. 2026-05-26 13:43 UTCEPSS rescore
  62. 2026-05-23 16:02 UTCEG score recompute
  63. 2026-05-23 16:02 UTCVendor advisory
  64. 2026-05-23 16:02 UTCGHSA enrichment

Frequently asked(5)

What is CVE-2024-53170?
CVE-2024-53170 is a high vulnerability published on December 27, 2024. In the Linux kernel, the following vulnerability has been resolved: block: fix uaf for flush rq while iterating tags blkmqclearflushrq_mapping() is not called during scsi probe, by checking blkqueueinitdone(). However, QUEUEFLAGINITDONE is cleared in delgendisk by commit aec89dc5d421 ("block: keep…
When was CVE-2024-53170 disclosed?
CVE-2024-53170 was first published in the National Vulnerability Database on December 27, 2024, with the most recent update on July 14, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2024-53170 actively exploited?
CVE-2024-53170 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 15.2% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
What is the CVSS score of CVE-2024-53170?
CVE-2024-53170 has a CVSS v3 base score of 7.8 (NVD).
How do I remediate CVE-2024-53170?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2024-53170, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2024-53170

Explore →

Is Your Infrastructure Affected by CVE-2024-53170?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.