PT-2024-33999 · Linux+7 · Linux Kernel+7
Published
2024-11-07
·
Updated
2025-10-03
·
CVE-2024-50167
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.61
Description:
A memory leak vulnerability has been identified in the Linux kernel's be2net component. The issue arises when the
be xmit() function returns NETDEV TX OK without freeing the skb in case of be xmit enqueue() failure. This can be resolved by adding dev kfree skb any() to fix the memory leak. The vulnerability poses a risk of local exploit.Recommendations:
For Linux kernel versions prior to 6.6.61, upgrade to version 6.6.61 or later to resolve the memory leak vulnerability. As a temporary workaround, consider restricting the use of the
be xmit() function until a patch is available.Exploit
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu