CVE-2024-0562: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A use-after-free flaw was found in the Linux Kernel. When a disk is removed, bdi_unregister is called to stop further write-back and waits for associated delayed work to complete. However, wb_inode_writeback_end() may schedule bandwidth estimation work after this has completed, which can result in the timer attempting to access the recently freed bdi_writeback.
Affected products
- Linux Linux Kernel: from 5.15, before 5.15.164 (fixed in 5.15.164); from 5.16, before 5.19.6 (fixed in 5.19.6); version 6.0 only
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
Published 2024-01-15. Last modified 2026-06-17.