PT-2024-33918 · Linux+6 · Linux Kernel+6

Syzbot

·

Published

2024-10-28

·

Updated

2025-10-03

·

CVE-2024-50085

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.12.0-rc2
Description: A use-after-free read vulnerability has been identified in the Linux kernel, specifically in the mptcp pm nl rm addr or subflow function. This issue was reported by Syzkaller and is related to a slab-use-after-free error in the net/mptcp/pm netlink.c file. The vulnerability occurs when the mptcp pm nl rm addr or subflow function attempts to access memory that has already been freed, leading to a potential crash or code execution. The mptcp pm nl rm addr or subflow function is called when removing an address or subflow, and the vulnerability is triggered when the genl family rcv msg doit function is invoked.
Recommendations: To resolve this issue, update the Linux kernel to a version that includes the fix for the mptcp: pm: fix UaF read in mptcp pm nl rm addr or subflow vulnerability. As a temporary workaround, consider disabling the mptcp pm nl rm addr or subflow function until a patch is available. However, this may have unintended consequences and should be approached with caution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-15251
ALT-PU-2024-17211
ALT-PU-2025-12647
AZL-51936
BDU:2025-03369
CVE-2024-50085
DLA-4008-1
OESA-2024-2492
OESA-2024-2493
OESA-2024-2494
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2025:14705-1
OPENSUSE-SU-2025_0847-1
OPENSUSE-SU-2025_0856-1
OPENSUSE-SU-2025_0955-1
SUSE-SU-2025:0784-1
SUSE-SU-2025:0847-1
SUSE-SU-2025:0856-1
SUSE-SU-2025:0955-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_0847-1
SUSE-SU-2025_0856-1
SUSE-SU-2025_0955-1
USN-7276-1
USN-7277-1
USN-7288-1
USN-7288-2
USN-7289-1
USN-7289-2
USN-7289-3
USN-7289-4
USN-7291-1
USN-7305-1
USN-7308-1
USN-7310-1
USN-7331-1
USN-7383-1
USN-7383-2
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7388-1
USN-7389-1
USN-7390-1
USN-7403-1
USN-7451-1
USN-7458-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu