PT-2024-34029 · Linux+10 · Linux Kernel+10

Published

2024-10-14

·

Updated

2026-02-12

·

CVE-2024-50195

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A vulnerability in the Linux kernel's posix-clock has been resolved. The issue was in the pc clock settime() function, where a missing timespec64 check allowed for potentially invalid time values to be passed to ptp->info->settime64(). According to the clock settime() manual, if tp.tv sec is negative or tp.tv nsec is outside the range [0..999,999,999], it should return EINVAL. The timespec64 valid() function only checks if the timespec is valid, but not if the time is in a valid range. To address this, timespec64 valid strict() is used to check the time range ahead of time and return -EINVAL if not valid. Some drivers, such as hclge ptp settime(), igb ptp settime i210(), and rcar gen4 ptp settime(), use tp->tv sec and tp->tv nsec directly to write registers without validity checks, assuming the higher layer has checked it, which is dangerous and will benefit from this fix.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:20518
ALT-PU-2024-14505
ALT-PU-2024-16172
ALT-PU-2024-17211
ALT-PU-2025-12647
AZL-53420
AZL-53739
BDU:2025-04361
CVE-2024-50195
DLA-4008-1
DLA-4075-1
INFSA-2025_20518
OESA-2024-2445
OESA-2024-2449
OESA-2024-2492
OESA-2024-2493
OESA-2024-2494
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2024_4376-1
OPENSUSE-SU-2025:14705-1
OPENSUSE-SU-2025_0556-1
OPENSUSE-SU-2025_0577-1
RHSA-2025:20518
RHSA-2025_20518
SUSE-SU-2024:4314-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4367-1
SUSE-SU-2024:4376-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:0035-1
SUSE-SU-2025:0556-1
SUSE-SU-2025:0577-1
SUSE-SU-2025:0577-2
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
SUSE-SU-2025_0577-1
SUSE-SU-2025_0577-2
USN-7276-1
USN-7277-1
USN-7288-1
USN-7288-2
USN-7289-1
USN-7289-2
USN-7289-3
USN-7289-4
USN-7291-1
USN-7293-1
USN-7294-1
USN-7294-2
USN-7294-3
USN-7294-4
USN-7295-1
USN-7305-1
USN-7308-1
USN-7310-1
USN-7331-1
USN-7383-1
USN-7383-2
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7388-1
USN-7389-1
USN-7390-1
USN-7393-1
USN-7401-1
USN-7403-1
USN-7413-1
USN-7451-1
USN-7458-1
USN-7468-1
USN-7523-1
USN-7524-1
USN-7539-1
USN-7540-1
USN-7987-1
USN-7987-2
USN-7988-1
USN-7988-2
USN-7988-3
USN-7988-4
USN-7988-5

Affected Products

Alt Linux
Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu