PT-2024-34102 · Linux+4 · Linux Kernel+4

Published

2024-11-04

·

Updated

2025-09-29

·

CVE-2024-50274

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.11.8
Description: A vulnerability in the Linux kernel has been resolved, specifically in the idpf get link ksettings function. When the device control plane is removed or the platform running the device control plane is rebooted, a reset is detected on the driver. If the reset fails, it takes the error path and releases the vport lock. At this time, if monitoring tools try to access link settings, it can lead to a call trace for accessing a released vport pointer. The issue is resolved by moving link speed mbps to the netdev priv structure, removing the dependency on the vport pointer and the vport lock in idpf get link ksettings. The netif carrier ok() function is used to check the link status, and the offsetof is adjusted to use link up instead of link speed mbps.
Recommendations: To resolve the issue, upgrade the Linux kernel to version 6.11.8 or later. As a temporary workaround, consider restricting access to the idpf get link ksettings function until a patch is available. Additionally, monitoring tools should be configured to avoid accessing link settings during a driver reset.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-17211
BDU:2025-07284
CVE-2024-50274
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2024_4346-1
OPENSUSE-SU-2024_4376-1
SUSE-SU-2024:4314-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4345-1
SUSE-SU-2024:4346-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4376-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7276-1
USN-7277-1
USN-7291-1
USN-7304-1
USN-7310-1
USN-7326-1
USN-7329-1
USN-7449-1
USN-7449-2
USN-7451-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Suse
Ubuntu