CVE-2024-0582Active Exploitation(linux / linux_kernel)

MEDIUMCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and then frees it. This flaw allows a local user to crash or potentially escalate their privileges on the system.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-04-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-13: 1Mentions · 2026-04-30: 1PoC Mentioned / Linked · 2026-04-30: 1Active Exploitation · 2026-04-13: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-30: 104-1304-30
Signal classification2 categories
Active Exploitation
150.0%
PoC
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-131
Active Exploitation1
2026-04-301
PoC1
Full discourse2 posts
  • ムワー@mk3uswh0l3
    PoC

    fr can't agree more! I remember trying to reproduce CVE-2024-0582, it's logical bug in io_uring and creating a testcase poc isn't that difficult (even i don't need to attach gdb to lookout the bug behavior).

    Post summary

    The author notes a logical bug in io_uring (CVE‑2024‑0582) and says producing a PoC test case is straightforward, with no mention of active exploitation, patches, or false positives.

    10002119
    146 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2024-0582 Exploit in the wild confirmed for CVE-2024-0582 (CVSS null). A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user r... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The post reports confirmed in‑the‑wild exploitation of CVE‑2024‑0582, highlighting a memory‑leak flaw in io_uring, but offers no exploit code, PoC, or patch information.

    0000080
    5.6K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.7--
OSlinuxlinux_kernel6.7--
OSlinuxlinux_kernel6.7--

Explore more