CVE-2024-27067: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: xen/evtchn: avoid WARN() when unbinding an event channel When unbinding a user event channel, the related handler might be called a last time in case the kernel was built with CONFIG_DEBUG_SHIRQ. This might cause a WARN() in the handler. Avoid that by adding an "unbinding" flag to struct user_event which will short circuit the handler.

Affected products

  • Linux Linux Kernel: from 6.6.19, before 6.6.23 (fixed in 6.6.23); from 6.7, before 6.7.11 (fixed in 6.7.11); from 6.8, before 6.8.2 (fixed in 6.8.2)

Published 2024-05-01. Last modified 2026-06-17.