PT-2024-33974 · Linux+11 · Linux Kernel+11

Syzbot

·

Published

2024-11-07

·

Updated

2026-05-19

·

CVE-2024-50142

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.61
Description: The issue involves the xfrm system in the Linux kernel. A vulnerability has been fixed where the prefix length of new SAs was not properly validated when the selector family was unset. This was exploited by syzbot, which created an SA with usersa.sel.family set to AF UNSPEC, usersa.sel.prefixlen s set to 128, and usersa.family set to AF INET. The verify newsa info function did not put limits on prefixlen {s,d} due to the AF UNSPEC selector, but later, copy from user state set x->sel.family to AF INET. To fix this, the validation in verify newsa info was expanded to convert the selector family before validating prefixlen {s,d}.
Recommendations: For Linux kernel versions prior to 6.6.61, update to version 6.6.61 or later to resolve the issue. As a temporary workaround, consider restricting the use of the xfrm system until a patch is available. Avoid using the usersa.sel.family set to AF UNSPEC in the affected xfrm system until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

ALSA-2024:10943
ALSA-2024:10944
ALSA-2024:11486
ALT-PU-2024-16172
ALT-PU-2024-17099
ALT-PU-2024-17211
ALT-PU-2025-12647
AZL-53474
AZL-53745
BDU:2025-03475
CESA-2024_10943
CESA-2024_10944
CVE-2024-50142
DLA-4008-1
DLA-4075-1
INFSA-2024_10943
INFSA-2024_10944
INFSA-2024_11486
MGASA-2024-0368
MGASA-2024-0369
OESA-2024-2424
OESA-2024-2425
OESA-2024-2426
OESA-2025-1034
OESA-2025-1078
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2025:14705-1
OPENSUSE-SU-2025_0556-1
OPENSUSE-SU-2025_0577-1
OPENSUSE-SU-2025_0847-1
OPENSUSE-SU-2025_0856-1
OPENSUSE-SU-2025_0955-1
RHSA-2024:10943
RHSA-2024:10944
RHSA-2024:11486
RHSA-2024_10943
RHSA-2024_10944
RHSA-2024_11486
RHSA-2025:1658
RLSA-2024:10943
RLSA-2024:10944
SUSE-SU-2025:0556-1
SUSE-SU-2025:0564-1
SUSE-SU-2025:0565-1
SUSE-SU-2025:0577-1
SUSE-SU-2025:0577-2
SUSE-SU-2025:0847-1
SUSE-SU-2025:0856-1
SUSE-SU-2025:0955-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_0577-1
SUSE-SU-2025_0577-2
SUSE-SU-2025_0847-1
SUSE-SU-2025_0856-1
SUSE-SU-2025_0955-1
USN-7276-1
USN-7277-1
USN-7288-1
USN-7288-2
USN-7289-1
USN-7289-2
USN-7289-3
USN-7289-4
USN-7291-1
USN-7293-1
USN-7294-1
USN-7294-2
USN-7294-3
USN-7294-4
USN-7295-1
USN-7305-1
USN-7308-1
USN-7310-1
USN-7331-1
USN-7388-1
USN-7389-1
USN-7390-1
USN-7393-1
USN-7401-1
USN-7413-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7458-1
USN-7468-1
USN-7523-1
USN-7524-1
USN-7539-1
USN-7540-1
USN-8266-1
USN-8267-1
USN-8274-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu