PT-2024-33878 · Linux+8 · Linux Kernel+8

Published

2024-10-21

·

Updated

2026-03-14

·

CVE-2024-50038

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.58
Description: A vulnerability has been resolved in the Linux kernel, specifically in the netfilter: xtables component. The issue arises when the xt cluster match is called via ebtables, causing a warning due to the module registering to NFPROTO UNSPEC but assuming ipv4/ipv6 packet processing. This is a general issue, as direct users of the set/getsockopt interface can call into targets/matches intended only for use with ip(6)tables. The problem occurs when matches and targets assume skb network header() is valid, which is only true when called from the inet layer. Targets that return XT CONTINUE or other xtables verdicts must also be restricted, as they are incompatible with the ebtables traverser.
Recommendations: For Linux kernel versions prior to 6.6.58, update to version 6.6.58 or later to resolve the issue. As a temporary workaround, consider restricting the use of the xt cluster match and other affected targets/matches to minimize the risk of exploitation. Additionally, ensure that the connbytes module is properly enabled to prevent failures in enabling the corresponding conntrack family.

Exploit

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17211
ALT-PU-2025-12647
AZL-51423
AZL-51452
BDU:2025-07939
CVE-2024-50038
DLA-4008-1
INFSA-2025_6966
MGASA-2024-0344
MGASA-2024-0345
OESA-2024-2491
OESA-2024-2492
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2025:14705-1
OPENSUSE-SU-2025_01614-1
OPENSUSE-SU-2025_01620-1
OPENSUSE-SU-2025_01640-1
OPENSUSE-SU-2025_01707-1
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2025:01600-1
SUSE-SU-2025:01614-1
SUSE-SU-2025:01620-1
SUSE-SU-2025:01640-1
SUSE-SU-2025:01707-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20206-1
SUSE-SU-2025:20270-1
SUSE-SU-2025:20283-1
SUSE-SU-2025_01600-1
SUSE-SU-2025_01614-1
SUSE-SU-2025_01620-1
SUSE-SU-2025_01707-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01967-1
USN-7166-1
USN-7166-2
USN-7166-3
USN-7166-4
USN-7186-1
USN-7186-2
USN-7194-1
USN-7276-1
USN-7277-1
USN-7310-1
USN-7383-1
USN-7383-2
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7403-1
USN-7451-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu