CVE-2024-50024 (GCVE-0-2024-50024)
Vulnerability from cvelistv5
Published
2024-10-21 19:39
Modified
2026-08-05 11:41
Summary
In the Linux kernel, the following vulnerability has been resolved: net: Fix an unsafe loop on the list The kernel may crash when deleting a genetlink family if there are still listeners for that family: Oops: Kernel access of bad area, sig: 11 [#1] ... NIP [c000000000c080bc] netlink_update_socket_mc+0x3c/0xc0 LR [c000000000c0f764] __netlink_clear_multicast_users+0x74/0xc0 Call Trace: __netlink_clear_multicast_users+0x74/0xc0 genl_unregister_family+0xd4/0x2d0 Change the unsafe loop on the list to a safe one, because inside the loop there is an element removal from this list.
Impacted products
Vendor Product Version
Linux Linux Version: b8273570f802a7658827dcb077b0b517ba75a289
Version: b8273570f802a7658827dcb077b0b517ba75a289
Version: b8273570f802a7658827dcb077b0b517ba75a289
Version: b8273570f802a7658827dcb077b0b517ba75a289
Version: b8273570f802a7658827dcb077b0b517ba75a289
Version: b8273570f802a7658827dcb077b0b517ba75a289
Version: b8273570f802a7658827dcb077b0b517ba75a289
Version: b8273570f802a7658827dcb077b0b517ba75a289
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-50024",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-10-22T13:27:00.388543Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-10-22T13:28:46.817Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:24:35.047Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "include/net/sock.h",
            "net/netlink/af_netlink.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "464801a0f6ccb52b21faa33bac6014fd74cc5e10",
              "status": "affected",
              "version": "b8273570f802a7658827dcb077b0b517ba75a289",
              "versionType": "git"
            },
            {
              "lessThan": "8e0766fcf37ad8eed289dd3853628dd9b01b58b0",
              "status": "affected",
              "version": "b8273570f802a7658827dcb077b0b517ba75a289",
              "versionType": "git"
            },
            {
              "lessThan": "68ad5da6ca630a276f0a5c924179e57724d00013",
              "status": "affected",
              "version": "b8273570f802a7658827dcb077b0b517ba75a289",
              "versionType": "git"
            },
            {
              "lessThan": "1cdec792b2450105b1314c5123a9a0452cb2c2f0",
              "status": "affected",
              "version": "b8273570f802a7658827dcb077b0b517ba75a289",
              "versionType": "git"
            },
            {
              "lessThan": "5f03a7f601f33cda1f710611625235dc86fd8a9e",
              "status": "affected",
              "version": "b8273570f802a7658827dcb077b0b517ba75a289",
              "versionType": "git"
            },
            {
              "lessThan": "3be342e0332a7c83eb26fbb22bf156fdca467a5d",
              "status": "affected",
              "version": "b8273570f802a7658827dcb077b0b517ba75a289",
              "versionType": "git"
            },
            {
              "lessThan": "49f9b726bf2bf3dd2caf0d27cadf4bc1ccf7a7dd",
              "status": "affected",
              "version": "b8273570f802a7658827dcb077b0b517ba75a289",
              "versionType": "git"
            },
            {
              "lessThan": "1dae9f1187189bc09ff6d25ca97ead711f7e26f9",
              "status": "affected",
              "version": "b8273570f802a7658827dcb077b0b517ba75a289",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "include/net/sock.h",
            "net/netlink/af_netlink.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.32"
            },
            {
              "lessThan": "2.6.32",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.323",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.285",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.227",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.168",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.113",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.57",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.323",
                  "versionStartIncluding": "2.6.32",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.285",
                  "versionStartIncluding": "2.6.32",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.227",
                  "versionStartIncluding": "2.6.32",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.168",
                  "versionStartIncluding": "2.6.32",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.113",
                  "versionStartIncluding": "2.6.32",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.57",
                  "versionStartIncluding": "2.6.32",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.4",
                  "versionStartIncluding": "2.6.32",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "2.6.32",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Fix an unsafe loop on the list\n\nThe kernel may crash when deleting a genetlink family if there are still\nlisteners for that family:\n\nOops: Kernel access of bad area, sig: 11 [#1]\n  ...\n  NIP [c000000000c080bc] netlink_update_socket_mc+0x3c/0xc0\n  LR [c000000000c0f764] __netlink_clear_multicast_users+0x74/0xc0\n  Call Trace:\n__netlink_clear_multicast_users+0x74/0xc0\ngenl_unregister_family+0xd4/0x2d0\n\nChange the unsafe loop on the list to a safe one, because inside the\nloop there is an element removal from this list."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The attacker-controlled state is built exclusively through local AF_NETLINK/NETLINK_GENERIC sockets (bind() and setsockopt(NETLINK_ADD_MEMBERSHIP)), and the faulty loop lives in netlink table maintenance code. There is no remote, adjacent-network, or guest-to-host path into `__netlink_clear_multicast_users()`.\nAC:L - The attacker deterministically constructs the dangerous `mc_list` \u2014 many sockets subscribed to many genl multicast group ids, with subscription counts arranged so the loop body unlinks the element it is standing on \u2014 and no condition outside their influence (specific timing window, unpredictable memory layout, or victim process state) is needed for the walk to leave the list.\nPR:L - NETLINK_GENERIC is registered with NL_CFG_F_NONROOT_RECV, so `netlink_allowed()` lets any unprivileged user join genl multicast groups, and `genl_bind()`\u0027s CAP_NET_ADMIN/CAP_SYS_ADMIN checks are `ns_capable(net-\u003euser_ns, \u2026)`, which a plain user satisfies via `unshare -Urn`; since `nl_table[].mc_list` is global and `genl_unregister_mc_groups()` sweeps every netns, sockets planted from an unprivileged namespace are walked by the buggy loop.\nUI:R - The unsafe loop only executes from `genl_unregister_family()`, which every in-tree caller reaches from a module exit or module-init failure path, so an administrator must unload/teardown the genl-providing module (rmmod, driver upgrade, udev-driven `modprobe -r`) after the attacker has planted the listeners.\nS:U - The stale list node, the netlink socket group bitmaps, and the corrupted slab memory all belong to the host kernel, the same security authority that is compromised. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The loop dereferences a list element already unlinked inside the body and reads through pointers taken from it (`test_bit(group - 1, nlk-\u003egroups)`), and the missing `ngroups` bound check \u2014 present in the sibling `netlink_update_listeners()` \u2014 makes that an out-of-bounds slab read at an attacker-chosen group index, a stale-object read primitive usable to disclose adjacent kernel heap contents.\nI:H - The same code path writes through the stale/undersized object \u2014 `__assign_bit(group - 1, nlk-\u003egroups, new)` and `nlk-\u003esubscriptions = subscriptions` \u2014 so once the freed or overrun slab region is groomed by the attacker this becomes an arbitrary-bit clear at an attacker-influenced address, plus corruption of the `mc_list` linkage itself, which is sufficient for control-flow hijacking.\nA:H - The committed reproduction is a hard kernel crash \u2014 \"Oops: Kernel access of bad area, sig: 11\" at `netlink_update_socket_mc+0x3c` under `__netlink_clear_multicast_users()` \u2014 and the corruption happens while `nl_table_lock` is held via `netlink_table_grab()` (`write_lock_irq`), so a mangled list also wedges the entire netlink subsystem."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:41:02.236Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/464801a0f6ccb52b21faa33bac6014fd74cc5e10"
        },
        {
          "url": "https://git.kernel.org/stable/c/8e0766fcf37ad8eed289dd3853628dd9b01b58b0"
        },
        {
          "url": "https://git.kernel.org/stable/c/68ad5da6ca630a276f0a5c924179e57724d00013"
        },
        {
          "url": "https://git.kernel.org/stable/c/1cdec792b2450105b1314c5123a9a0452cb2c2f0"
        },
        {
          "url": "https://git.kernel.org/stable/c/5f03a7f601f33cda1f710611625235dc86fd8a9e"
        },
        {
          "url": "https://git.kernel.org/stable/c/3be342e0332a7c83eb26fbb22bf156fdca467a5d"
        },
        {
          "url": "https://git.kernel.org/stable/c/49f9b726bf2bf3dd2caf0d27cadf4bc1ccf7a7dd"
        },
        {
          "url": "https://git.kernel.org/stable/c/1dae9f1187189bc09ff6d25ca97ead711f7e26f9"
        }
      ],
      "title": "net: Fix an unsafe loop on the list",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-50024",
    "datePublished": "2024-10-21T19:39:29.203Z",
    "dateReserved": "2024-10-21T12:17:06.065Z",
    "dateUpdated": "2026-08-05T11:41:02.236Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html\"}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T22:24:35.047Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-50024\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-10-22T13:27:00.388543Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-10-22T13:27:03.641Z\"}}], \"cna\": {\"title\": \"net: Fix an unsafe loop on the list\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.3, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The attacker-controlled state is built exclusively through local AF_NETLINK/NETLINK_GENERIC sockets (bind() and setsockopt(NETLINK_ADD_MEMBERSHIP)), and the faulty loop lives in netlink table maintenance code. There is no remote, adjacent-network, or guest-to-host path into `__netlink_clear_multicast_users()`.\\nAC:L - The attacker deterministically constructs the dangerous `mc_list` \\u2014 many sockets subscribed to many genl multicast group ids, with subscription counts arranged so the loop body unlinks the element it is standing on \\u2014 and no condition outside their influence (specific timing window, unpredictable memory layout, or victim process state) is needed for the walk to leave the list.\\nPR:L - NETLINK_GENERIC is registered with NL_CFG_F_NONROOT_RECV, so `netlink_allowed()` lets any unprivileged user join genl multicast groups, and `genl_bind()`\u0027s CAP_NET_ADMIN/CAP_SYS_ADMIN checks are `ns_capable(net-\u003euser_ns, \\u2026)`, which a plain user satisfies via `unshare -Urn`; since `nl_table[].mc_list` is global and `genl_unregister_mc_groups()` sweeps every netns, sockets planted from an unprivileged namespace are walked by the buggy loop.\\nUI:R - The unsafe loop only executes from `genl_unregister_family()`, which every in-tree caller reaches from a module exit or module-init failure path, so an administrator must unload/teardown the genl-providing module (rmmod, driver upgrade, udev-driven `modprobe -r`) after the attacker has planted the listeners.\\nS:U - The stale list node, the netlink socket group bitmaps, and the corrupted slab memory all belong to the host kernel, the same security authority that is compromised. No VM, IOMMU, or sandbox boundary is crossed.\\nC:H - The loop dereferences a list element already unlinked inside the body and reads through pointers taken from it (`test_bit(group - 1, nlk-\u003egroups)`), and the missing `ngroups` bound check \\u2014 present in the sibling `netlink_update_listeners()` \\u2014 makes that an out-of-bounds slab read at an attacker-chosen group index, a stale-object read primitive usable to disclose adjacent kernel heap contents.\\nI:H - The same code path writes through the stale/undersized object \\u2014 `__assign_bit(group - 1, nlk-\u003egroups, new)` and `nlk-\u003esubscriptions = subscriptions` \\u2014 so once the freed or overrun slab region is groomed by the attacker this becomes an arbitrary-bit clear at an attacker-influenced address, plus corruption of the `mc_list` linkage itself, which is sufficient for control-flow hijacking.\\nA:H - The committed reproduction is a hard kernel crash \\u2014 \\\"Oops: Kernel access of bad area, sig: 11\\\" at `netlink_update_socket_mc+0x3c` under `__netlink_clear_multicast_users()` \\u2014 and the corruption happens while `nl_table_lock` is held via `netlink_table_grab()` (`write_lock_irq`), so a mangled list also wedges the entire netlink subsystem.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"b8273570f802a7658827dcb077b0b517ba75a289\", \"lessThan\": \"464801a0f6ccb52b21faa33bac6014fd74cc5e10\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b8273570f802a7658827dcb077b0b517ba75a289\", \"lessThan\": \"8e0766fcf37ad8eed289dd3853628dd9b01b58b0\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b8273570f802a7658827dcb077b0b517ba75a289\", \"lessThan\": \"68ad5da6ca630a276f0a5c924179e57724d00013\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b8273570f802a7658827dcb077b0b517ba75a289\", \"lessThan\": \"1cdec792b2450105b1314c5123a9a0452cb2c2f0\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b8273570f802a7658827dcb077b0b517ba75a289\", \"lessThan\": \"5f03a7f601f33cda1f710611625235dc86fd8a9e\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b8273570f802a7658827dcb077b0b517ba75a289\", \"lessThan\": \"3be342e0332a7c83eb26fbb22bf156fdca467a5d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b8273570f802a7658827dcb077b0b517ba75a289\", \"lessThan\": \"49f9b726bf2bf3dd2caf0d27cadf4bc1ccf7a7dd\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b8273570f802a7658827dcb077b0b517ba75a289\", \"lessThan\": \"1dae9f1187189bc09ff6d25ca97ead711f7e26f9\", \"versionType\": \"git\"}], \"programFiles\": [\"include/net/sock.h\", \"net/netlink/af_netlink.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"2.6.32\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"2.6.32\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"4.19.323\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"4.19.*\"}, {\"status\": \"unaffected\", \"version\": \"5.4.285\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.227\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.168\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.113\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.57\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.4\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"include/net/sock.h\", \"net/netlink/af_netlink.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/464801a0f6ccb52b21faa33bac6014fd74cc5e10\"}, {\"url\": \"https://git.kernel.org/stable/c/8e0766fcf37ad8eed289dd3853628dd9b01b58b0\"}, {\"url\": \"https://git.kernel.org/stable/c/68ad5da6ca630a276f0a5c924179e57724d00013\"}, {\"url\": \"https://git.kernel.org/stable/c/1cdec792b2450105b1314c5123a9a0452cb2c2f0\"}, {\"url\": \"https://git.kernel.org/stable/c/5f03a7f601f33cda1f710611625235dc86fd8a9e\"}, {\"url\": \"https://git.kernel.org/stable/c/3be342e0332a7c83eb26fbb22bf156fdca467a5d\"}, {\"url\": \"https://git.kernel.org/stable/c/49f9b726bf2bf3dd2caf0d27cadf4bc1ccf7a7dd\"}, {\"url\": \"https://git.kernel.org/stable/c/1dae9f1187189bc09ff6d25ca97ead711f7e26f9\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nnet: Fix an unsafe loop on the list\\n\\nThe kernel may crash when deleting a genetlink family if there are still\\nlisteners for that family:\\n\\nOops: Kernel access of bad area, sig: 11 [#1]\\n  ...\\n  NIP [c000000000c080bc] netlink_update_socket_mc+0x3c/0xc0\\n  LR [c000000000c0f764] __netlink_clear_multicast_users+0x74/0xc0\\n  Call Trace:\\n__netlink_clear_multicast_users+0x74/0xc0\\ngenl_unregister_family+0xd4/0x2d0\\n\\nChange the unsafe loop on the list to a safe one, because inside the\\nloop there is an element removal from this list.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.19.323\", \"versionStartIncluding\": \"2.6.32\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.285\", \"versionStartIncluding\": \"2.6.32\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.227\", \"versionStartIncluding\": \"2.6.32\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.168\", \"versionStartIncluding\": \"2.6.32\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.113\", \"versionStartIncluding\": \"2.6.32\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.57\", \"versionStartIncluding\": \"2.6.32\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.4\", \"versionStartIncluding\": \"2.6.32\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12\", \"versionStartIncluding\": \"2.6.32\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:41:02.236Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-50024\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:41:02.236Z\", \"dateReserved\": \"2024-10-21T12:17:06.065Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-10-21T19:39:29.203Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…