PT-2024-10002 · Linux+6 · Linux Kernel+6

Published

2024-11-06

·

Updated

2025-10-03

·

CVE-2024-50276

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.23
Description The issue is related to a double free vulnerability in the mse102x tx frame spi() function within the Linux kernel. This vulnerability can lead to crashes and potentially allow an attacker to impact the confidentiality, integrity, and availability of protected information. The scope of the TX skb is wider than just mse102x tx frame spi(), and when the TX skb room needs to be expanded, freeing the temporary skb instead of the original skb is necessary to prevent the original TX skb pointer from being freed again in mse102x tx work(). This can cause crashes, as indicated by the internal error message.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the double free vulnerability in the mse102x tx frame spi() function. As a temporary workaround, consider disabling the mse102x tx frame spi() function until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using the mse102x tx work() function in the affected kernel version until the issue is resolved.

Exploit

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-16040
ALT-PU-2024-17211
ALT-PU-2024-17891
ALT-PU-2025-12647
BDU:2025-00129
CVE-2024-50276
DLA-4008-1
DSA-5818-1
OESA-2024-2492
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4316-1
SUSE-SU-2024:4314-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7276-1
USN-7277-1
USN-7310-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu