{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu16.04els/vex/2024/cve-2024-53140-els_os-ubuntu16_04els.json"
      }
    ],
    "title": "Security update on CVE-2024-53140",
    "tracking": {
      "current_release_date": "2025-12-23T22:15:38Z",
      "generator": {
        "date": "2025-12-23T22:15:38Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2024-53140-ELS_OS-UBUNTU16.04ELS",
      "initial_release_date": "2024-12-04T15:15:00Z",
      "revision_history": [
        {
          "date": "2024-12-04T15:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2025-05-16T21:19:09Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2025-12-23T22:15:38Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "2"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 16.04",
                "product": {
                  "name": "Ubuntu 16.04",
                  "product_id": "Ubuntu-16",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "linux-libc-dev-0:4.4.0-274.308.amd64",
                "product": {
                  "name": "linux-libc-dev-0:4.4.0-274.308.amd64",
                  "product_id": "linux-libc-dev-0:4.4.0-274.308.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/linux-libc-dev@4.4.0-274.308?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-cloud-tools-4.4.0-274-tuxcare.els45-generic-0:4.4.0-274.308.amd64",
                "product": {
                  "name": "linux-cloud-tools-4.4.0-274-tuxcare.els45-generic-0:4.4.0-274.308.amd64",
                  "product_id": "linux-cloud-tools-4.4.0-274-tuxcare.els45-generic-0:4.4.0-274.308.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/linux-cloud-tools-4.4.0-274-tuxcare.els45-generic@4.4.0-274.308?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-tools-generic-0:4.4.0.274.308.amd64",
                "product": {
                  "name": "linux-tools-generic-0:4.4.0.274.308.amd64",
                  "product_id": "linux-tools-generic-0:4.4.0.274.308.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/linux-tools-generic@4.4.0.274.308?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-image-lowlatency-0:4.4.0.274.308.amd64",
                "product": {
                  "name": "linux-image-lowlatency-0:4.4.0.274.308.amd64",
                  "product_id": "linux-image-lowlatency-0:4.4.0.274.308.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/linux-image-lowlatency@4.4.0.274.308?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-lowlatency-0:4.4.0.274.308.amd64",
                "product": {
                  "name": "linux-lowlatency-0:4.4.0.274.308.amd64",
                  "product_id": "linux-lowlatency-0:4.4.0.274.308.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/linux-lowlatency@4.4.0.274.308?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-headers-lowlatency-0:4.4.0.274.308.amd64",
                "product": {
                  "name": "linux-headers-lowlatency-0:4.4.0.274.308.amd64",
                  "product_id": "linux-headers-lowlatency-0:4.4.0.274.308.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/linux-headers-lowlatency@4.4.0.274.308?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-buildinfo-4.4.0-274-tuxcare.els45-lowlatency-0:4.4.0-274.308.amd64",
                "product": {
                  "name": "linux-buildinfo-4.4.0-274-tuxcare.els45-lowlatency-0:4.4.0-274.308.amd64",
                  "product_id": "linux-buildinfo-4.4.0-274-tuxcare.els45-lowlatency-0:4.4.0-274.308.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/linux-buildinfo-4.4.0-274-tuxcare.els45-lowlatency@4.4.0-274.308?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-tools-lowlatency-0:4.4.0.274.308.amd64",
                "product": {
                  "name": "linux-tools-lowlatency-0:4.4.0.274.308.amd64",
                  "product_id": "linux-tools-lowlatency-0:4.4.0.274.308.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/linux-tools-lowlatency@4.4.0.274.308?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "linux-tools-host-0:4.4.0-274.308.all",
                "product": {
                  "name": "linux-tools-host-0:4.4.0-274.308.all",
                  "product_id": "linux-tools-host-0:4.4.0-274.308.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/linux-tools-host@4.4.0-274.308?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-source-4.4.0-0:4.4.0-274.308.all",
                "product": {
                  "name": "linux-source-4.4.0-0:4.4.0-274.308.all",
                  "product_id": "linux-source-4.4.0-0:4.4.0-274.308.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/linux-source-4.4.0@4.4.0-274.308?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-libc-dev-0:4.4.0-274.308.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:linux-libc-dev-0:4.4.0-274.308.amd64"
        },
        "product_reference": "linux-libc-dev-0:4.4.0-274.308.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-cloud-tools-4.4.0-274-tuxcare.els45-generic-0:4.4.0-274.308.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:linux-cloud-tools-4.4.0-274-tuxcare.els45-generic-0:4.4.0-274.308.amd64"
        },
        "product_reference": "linux-cloud-tools-4.4.0-274-tuxcare.els45-generic-0:4.4.0-274.308.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-tools-host-0:4.4.0-274.308.all as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:linux-tools-host-0:4.4.0-274.308.all"
        },
        "product_reference": "linux-tools-host-0:4.4.0-274.308.all",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-tools-generic-0:4.4.0.274.308.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:linux-tools-generic-0:4.4.0.274.308.amd64"
        },
        "product_reference": "linux-tools-generic-0:4.4.0.274.308.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-source-4.4.0-0:4.4.0-274.308.all as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:linux-source-4.4.0-0:4.4.0-274.308.all"
        },
        "product_reference": "linux-source-4.4.0-0:4.4.0-274.308.all",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-image-lowlatency-0:4.4.0.274.308.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:linux-image-lowlatency-0:4.4.0.274.308.amd64"
        },
        "product_reference": "linux-image-lowlatency-0:4.4.0.274.308.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-lowlatency-0:4.4.0.274.308.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:linux-lowlatency-0:4.4.0.274.308.amd64"
        },
        "product_reference": "linux-lowlatency-0:4.4.0.274.308.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-headers-lowlatency-0:4.4.0.274.308.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:linux-headers-lowlatency-0:4.4.0.274.308.amd64"
        },
        "product_reference": "linux-headers-lowlatency-0:4.4.0.274.308.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-buildinfo-4.4.0-274-tuxcare.els45-lowlatency-0:4.4.0-274.308.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:linux-buildinfo-4.4.0-274-tuxcare.els45-lowlatency-0:4.4.0-274.308.amd64"
        },
        "product_reference": "linux-buildinfo-4.4.0-274-tuxcare.els45-lowlatency-0:4.4.0-274.308.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-tools-lowlatency-0:4.4.0.274.308.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:linux-tools-lowlatency-0:4.4.0.274.308.amd64"
        },
        "product_reference": "linux-tools-lowlatency-0:4.4.0.274.308.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-53140",
      "notes": [
        {
          "category": "description",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlink: terminate outstanding dump on socket close\n\nNetlink supports iterative dumping of data. It provides the families\nthe following ops:\n - start - (optional) kicks off the dumping process\n - dump  - actual dump helper, keeps getting called until it returns 0\n - done  - (optional) pairs with .start, can be used for cleanup\nThe whole process is asynchronous and the repeated calls to .dump\ndon't actually happen in a tight loop, but rather are triggered\nin response to recvmsg() on the socket.\n\nThis gives the user full control over the dump, but also means that\nthe user can close the socket without getting to the end of the dump.\nTo make sure .start is always paired with .done we check if there\nis an ongoing dump before freeing the socket, and if so call .done.\n\nThe complication is that sockets can get freed from BH and .done\nis allowed to sleep. So we use a workqueue to defer the call, when\nneeded.\n\nUnfortunately this does not work correctly. What we defer is not\nthe cleanup but rather releasing a reference on the socket.\nWe have no guarantee that we own the last reference, if someone\nelse holds the socket they may release it in BH and we're back\nto square one.\n\nThe whole dance, however, appears to be unnecessary. Only the user\ncan interact with dumps, so we can clean up when socket is closed.\nAnd close always happens in process context. Some async code may\nstill access the socket after close, queue notification skbs to it etc.\nbut no dumps can start, end or otherwise make progress.\n\nDelete the workqueue and flush the dump state directly from the release\nhandler. Note that further cleanup is possible in -next, for instance\nwe now always call .done before releasing the main module reference,\nso dump doesn't have to take a reference of its own.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-16:linux-libc-dev-0:4.4.0-274.308.amd64",
          "Ubuntu-16:linux-cloud-tools-4.4.0-274-tuxcare.els45-generic-0:4.4.0-274.308.amd64",
          "Ubuntu-16:linux-tools-host-0:4.4.0-274.308.all",
          "Ubuntu-16:linux-tools-generic-0:4.4.0.274.308.amd64",
          "Ubuntu-16:linux-source-4.4.0-0:4.4.0-274.308.all",
          "Ubuntu-16:linux-image-lowlatency-0:4.4.0.274.308.amd64",
          "Ubuntu-16:linux-lowlatency-0:4.4.0.274.308.amd64",
          "Ubuntu-16:linux-headers-lowlatency-0:4.4.0.274.308.amd64",
          "Ubuntu-16:linux-buildinfo-4.4.0-274-tuxcare.els45-lowlatency-0:4.4.0-274.308.amd64",
          "Ubuntu-16:linux-tools-lowlatency-0:4.4.0.274.308.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-53140"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/114a61d8d94ae3a43b82446cf737fd757021b834",
          "url": "https://git.kernel.org/stable/c/114a61d8d94ae3a43b82446cf737fd757021b834"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/176c41b3ca9281a9736b67c6121b03dbf0c8c08f",
          "url": "https://git.kernel.org/stable/c/176c41b3ca9281a9736b67c6121b03dbf0c8c08f"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/1904fb9ebf911441f90a68e96b22aa73e4410505",
          "url": "https://git.kernel.org/stable/c/1904fb9ebf911441f90a68e96b22aa73e4410505"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/4e87a52133284afbd40fb522dbf96e258af52a98",
          "url": "https://git.kernel.org/stable/c/4e87a52133284afbd40fb522dbf96e258af52a98"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/598c956b62699c3753929602560d8df322e60559",
          "url": "https://git.kernel.org/stable/c/598c956b62699c3753929602560d8df322e60559"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/6e3f2c512d2b7dbd247485b1dd9e43e4210a18f4",
          "url": "https://git.kernel.org/stable/c/6e3f2c512d2b7dbd247485b1dd9e43e4210a18f4"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/bbc769d2fa1b8b368c5fbe013b5b096afa3c05ca",
          "url": "https://git.kernel.org/stable/c/bbc769d2fa1b8b368c5fbe013b5b096afa3c05ca"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/d2fab3d66cc16cfb9e3ea1772abe6b79b71fa603",
          "url": "https://git.kernel.org/stable/c/d2fab3d66cc16cfb9e3ea1772abe6b79b71fa603"
        }
      ],
      "release_date": "2024-12-04T15:15:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Ubuntu-16:linux-libc-dev-0:4.4.0-274.308.amd64",
            "Ubuntu-16:linux-cloud-tools-4.4.0-274-tuxcare.els45-generic-0:4.4.0-274.308.amd64",
            "Ubuntu-16:linux-tools-host-0:4.4.0-274.308.all",
            "Ubuntu-16:linux-tools-generic-0:4.4.0.274.308.amd64",
            "Ubuntu-16:linux-source-4.4.0-0:4.4.0-274.308.all",
            "Ubuntu-16:linux-image-lowlatency-0:4.4.0.274.308.amd64",
            "Ubuntu-16:linux-lowlatency-0:4.4.0.274.308.amd64",
            "Ubuntu-16:linux-headers-lowlatency-0:4.4.0.274.308.amd64",
            "Ubuntu-16:linux-buildinfo-4.4.0-274-tuxcare.els45-lowlatency-0:4.4.0-274.308.amd64",
            "Ubuntu-16:linux-tools-lowlatency-0:4.4.0.274.308.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Medium"
        }
      ]
    }
  ]
}