CVE-2024-0582
HIGH 7.8EPSS 12.8%
A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and then frees it. This flaw allows a local user to crash or potentially escalate their privileges on the system.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 12.84% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2024-01-16
- Updated
- 2025-11-20
Proof-of-concept exploits (11)
- 0ptyx/cve-2024-05820★ · 2024-05-28
- 101010zyl/CVE-2024-05825★ · 2024-12-15
- 101010zyl/CVE-2024-0582-dataonly5★ · 2024-12-15
- Forsaken0129/CVE-2024-05820★ · 2024-04-05
- Forsaken0129/UltimateLinuxPrivilage0★ · 2024-04-05
- geniuszly/CVE-2024-058213★ · 2024-10-03
- geniuszlyy/CVE-2024-058213★ · 2024-10-03
- kuzeyardabulut/CVE-2024-058213★ · 2025-04-16
- pwnmonk/io_uring-n-day0★ · 2025-09-26
- ysanatomic/io_uring_LPE-CVE-2024-0582101★ · 2024-03-29
- nanabingies/CVE-2024-0582