CVE-2024-47675 is a use-after-free vulnerability in the Linux kernel's BPF subsystem, specifically within the bpf_uprobe_multi_link_attach() function. This flaw, rated High severity (CVSS 7.8), occurs when bpf_link_prime() fails, leading to the premature freeing of bpf_uprobe structures without proper unregistration, resulting in leaked uprobe objects and orphaned consumer entries. An attacker with local access could potentially exploit this to achieve high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.6, < 6.6.54CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.10.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.11, < 6.11.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025CVE-2024-47675
Nov 12, 2024kernel: bpf: Fix use-after-free in bpf_uprobe_multi_link_attach()
Oct 21, 2024bpf: Fix use-after-free in bpf_uprobe_multi_link_attach()
Oct 8, 2024