PT-2024-33876 · Linux+7 · Linux Kernel+7

Naresh Kamboju

·

Published

2024-10-10

·

Updated

2025-10-03

·

CVE-2024-50036

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.58
Description: A vulnerability in the Linux kernel has been resolved, related to the dst entries add() function using per-cpu data that might be freed at netns dismantle from ip6 route net exit() calling dst entries destroy(). This can cause a race condition, as dst entries destroy() could have been called already. The issue is also related to the dst release() function, which waits an rcu grace period before calling dst destroy(). Additionally, in the CONFIG XFRM case, dst destroy() can call dst release immediate(child), potentially causing a use-after-free (UAF) issue if the child does not have DST NOCOUNT set.
Recommendations: For Linux kernel versions prior to 6.6.58, update to version 6.6.58 or later to resolve the issue. As a temporary workaround, consider disabling the dst entries add() function until a patch is available. Restrict access to the dst release() function to minimize the risk of exploitation. Avoid using the dst entries destroy() function in conjunction with dst release() until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17211
ALT-PU-2025-12647
AZL-51365
AZL-51476
BDU:2025-04685
CVE-2024-50036
DLA-4008-1
DLA-4075-1
DSA-5818-1
MGASA-2024-0344
MGASA-2024-0345
OESA-2024-2321
OESA-2024-2322
OESA-2024-2323
OESA-2024-2324
OESA-2024-2367
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2025:14705-1
OPENSUSE-SU-2025_0847-1
OPENSUSE-SU-2025_0856-1
OPENSUSE-SU-2025_0955-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:0834-1
SUSE-SU-2025:0847-1
SUSE-SU-2025:0856-1
SUSE-SU-2025:0955-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_0834-1
SUSE-SU-2025_0847-1
SUSE-SU-2025_0856-1
SUSE-SU-2025_0955-1
USN-7276-1
USN-7277-1
USN-7288-1
USN-7288-2
USN-7289-1
USN-7289-2
USN-7289-3
USN-7289-4
USN-7291-1
USN-7305-1
USN-7308-1
USN-7310-1
USN-7331-1
USN-7383-1
USN-7383-2
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7388-1
USN-7389-1
USN-7390-1
USN-7403-1
USN-7451-1
USN-7458-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu