Critical· 9.8official fix available
CVE-2024-42232
CVE-2024-42232 is a critical race condition vulnerability in the Linux kernel's libceph component. It allows attackers to exploit a timing issue during session termination, potentially leading to use-after-free errors and unauthorized access to sensitive data. The vulnerability has been resolved in a kernel patch.
publishedAug 7, 2024
last modifiedAug 4, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
13th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 4, 2026
An official fix is available, so this entry is kept for 30 days and then removed automatically.
01
Who is affected
Systems using the Linux kernel with the libceph component.
02
Real-world impact
Could allow attackers to crash systems or gain unauthorized access to sensitive data stored in the libceph subsystem.
03
Why this severity
CVSS 9.8 (critical) due to high confidence in exploitation and potential for full system compromise.
04
What to do about it
official fix available
recommended steps
- 01Upgrade the Linux kernel to a version that includes the fix for CVE-2024-42232.
- 02Apply the kernel patch provided by maintainers if an immediate upgrade is not possible.
NVD-referenced vendor advisory (Linux kernel patch notes)
05
Timeline
- Aug 7, 2024 · Aug 7, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
06
How it’s attacked
Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07
References & advisories
- git.kernel.org/stable/c/1177afeca833174ba8…patch
- git.kernel.org/stable/c/20cf67dcb7db842f94…patch
- git.kernel.org/stable/c/2d33654d40a05afd91…patch
- git.kernel.org/stable/c/33d38c5da17f8db2d8…patch
- git.kernel.org/stable/c/34b76d1922e41da1fa…patch
- git.kernel.org/stable/c/63e5d035e3a7ab7412…patch
- git.kernel.org/stable/c/69c7b2fe4c9cc1d3b1…patch
- git.kernel.org/stable/c/9525af1f58f67df387…patch
- lists.debian.org/debian-lts-announce/2025/01…
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →