
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-45007 affects the Linux kernel's xillybus character device driver. The vulnerability was discovered and disclosed on September 4, 2024. The issue occurs when destroy_workqueue() may be called from within a work item attempting to destroy its own workqueue, triggered by a kref decrement (Kernel Git).
The vulnerability exists in the Linux kernel's char/xillybus subsystem. The technical issue involves an illegal situation where a workqueue is destroyed from within a work item running on that same workqueue. The fix involves adding a module-global workqueue for exclusive use of the offending work item, while other work items continue to be queued on per-device workqueues to maintain performance (Kernel Git).
The vulnerability affects various Linux kernel versions and distributions including Ubuntu 22.04 LTS, 24.04 LTS, and other versions. Multiple kernel packages required updates to address this issue (Ubuntu Security).
The issue has been fixed in various Linux kernel versions. Ubuntu has released patches for affected versions: 6.8.0-50.51 for 24.04 LTS (noble) and 5.15.0-125.135 for 22.04 LTS (jammy). Users are advised to update their systems to the patched versions (Ubuntu Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."