CVE-2024-50024

Scores

EPSS

0.000Very Low0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

4.7Medium3.x
0246810

CVSS Score: 4.7/10

All CVSS Scores

CVSS 3.x
4.7

Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

net: Fix an unsafe loop on the list

The kernel may crash when deleting a genetlink family if there are still
listeners for that family:

Oops: Kernel access of bad area, sig: 11 [#1]

NIP [c000000000c080bc] netlink_update_socket_mc+0x3c/0xc0
LR [c000000000c0f764] __netlink_clear_multicast_users+0x74/0xc0
Call Trace:
__netlink_clear_multicast_users+0x74/0xc0
genl_unregister_family+0xd4/0x2d0

Change the unsafe loop on the list to a safe one, because inside the
loop there is an element removal from this list.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

astradebiannvdubuntu

CWEs

CWE-404

Related Vulnerabilities

Vulnerable Software (160)

Type: Configuration

Product: linux

Operating System: ubuntu trusty 14.04

Trait:
{
  "unfixed": true
}

Source: ubuntu

Type: Configuration

Product: linux

Operating System: debian

Trait:
{
  "fixed": "6.11.4-1"
}

Source: debian

Type: Configuration

Product: linux

Operating System: debian bookworm 12

Trait:
{
  "fixed": "6.1.115-1"
}

Source: debian

Type: Configuration

Product: linux

Operating System: ubuntu bionic 18.04

Trait:
{
  "unfixed": true
}

Source: ubuntu

Type: Configuration

Product: linux

Operating System: ubuntu focal 20.04

Trait:
{
  "fixed": "5.4.0-208.228"
}

Source: ubuntu

Type: Configuration

Product: linux

Operating System: ubuntu jammy 22.04

Trait:
{
  "fixed": "5.15.0-127.137"
}

Source: ubuntu

Type: Configuration

Product: linux

Operating System: ubuntu xenial 16.04

Trait:
{
  "unfixed": true
}

Source: ubuntu

Type: Configuration

Product: linux-6.1

Operating System: astra 4.7.7.4

Trait:
{
  "unaffected": true
}

Source: astra

Type: Configuration

Product: linux-allwinner-5.19

Operating System: ubuntu jammy 22.04

Trait:
{
  "unfixed": true
}

Source: ubuntu

Type: Configuration

Product: linux-aws

Operating System: ubuntu trusty 14.04

Trait:
{
  "unfixed": true
}

Source: ubuntu