PT-2024-34085 · Linux+8 · Linux Kernel+8
Maksym Yaremchuk
·
Published
2024-10-25
·
Updated
2025-10-03
·
CVE-2024-50252
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.61
Description:
A memory leak issue has been identified in the Linux kernel, specifically in the mlxsw spectrum ipip module. This issue occurs when changing the remote IPv6 address of an ip6gre net device, resulting in a warning and a memory leak. The problem arises because the new remote address is not added to the driver's hash table, and the old address is not removed. This issue can be triggered by changing the remote address of an ip6gre net device using the
ip link set command.Recommendations:
To resolve this issue, update the Linux kernel to version 6.6.61 or later. As a temporary workaround, consider avoiding changes to the remote IPv6 address of ip6gre net devices until the update is applied. Additionally, restrict access to the vulnerable module
mlxsw to minimize the risk of exploitation.Exploit
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu