PT-2024-33711 · Linux+5 · Linux Kernel+5

Wei Li

·

Published

2024-09-24

·

Updated

2025-04-28

·

CVE-2024-49866

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.58
Description: A race condition during cpuhp processing in the Linux kernel's tracing/timerlat component can lead to timer corruption. This issue occurs when the "timerlat/1" thread is scheduled on CPU0, and the CPU may have already been removed from the cpu online mask during the offline process, resulting in the inability to select the right CPU. The problem arises from the asynchronous implementation of CPU online processing for osnoise through workers.
Recommendations: To resolve this issue, update to Linux kernel version 6.6.58 or later. As a temporary workaround, consider disabling the timerlat functionality until a patch is available. Restrict access to the tracing/timerlat component to minimize the risk of exploitation. Avoid using the timerlat irq function in the affected kernel versions until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-53343
BDU:2025-03129
CVE-2024-49866
DLA-4008-1
MGASA-2024-0344
MGASA-2024-0345
OESA-2024-2321
OESA-2024-2322
OESA-2024-2324
OESA-2024-2325
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2024_3983-1
OPENSUSE-SU-2024_3984-1
OPENSUSE-SU-2024_3985-1
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2025:14705-1
SUSE-SU-2024:3983-1
SUSE-SU-2024:3984-1
SUSE-SU-2024:3985-1
SUSE-SU-2024:4314-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7166-1
USN-7166-2
USN-7166-3
USN-7166-4
USN-7186-1
USN-7186-2
USN-7194-1
USN-7276-1
USN-7277-1
USN-7301-1
USN-7303-1
USN-7303-2
USN-7303-3
USN-7304-1
USN-7310-1
USN-7311-1
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7403-1
USN-7468-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu