PT-2024-7567 · Linux+7 · Linux Kernel+7

Kaixin Wang

·

Published

2024-09-17

·

Updated

2026-05-26

·

CVE-2024-50061

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.58
Description The issue is related to a use-after-free vulnerability in the cdns i3c master driver due to a race condition. This vulnerability can be exploited to impact the confidentiality, integrity, and availability of protected information. The vulnerability occurs when the cdns i3c master remove function is called, which frees the master->base resource, but the cdns i3c master hj work is still bound to it and can be used by the i3c master do daa function, leading to a use-after-free bug.
Recommendations To resolve the issue, ensure that the work is canceled before proceeding with the cleanup in cdns i3c master remove. Update to Linux kernel version 6.6.58 or later, which includes the fix for this vulnerability. As a temporary workaround, consider disabling the cdns i3c master driver until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using the master->base resource in the affected API endpoints until the issue is resolved.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-14704
ALT-PU-2024-17211
ALT-PU-2025-12647
AZL-50806
AZL-50839
BDU:2024-08973
CVE-2024-50061
DLA-4102-1
MGASA-2024-0344
MGASA-2024-0345
OESA-2024-2446
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2024_3983-1
OPENSUSE-SU-2024_3984-1
OPENSUSE-SU-2024_3985-1
OPENSUSE-SU-2024_3986-1
OPENSUSE-SU-2025:14705-1
SUSE-SU-2024:3983-1
SUSE-SU-2024:3984-1
SUSE-SU-2024:3985-1
SUSE-SU-2024:3986-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7276-1
USN-7277-1
USN-7310-1
USN-7383-1
USN-7383-2
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7403-1
USN-7451-1
USN-7468-1
USN-7523-1
USN-7524-1
USN-7874-1
USN-7874-2
USN-7874-3
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7938-1
USN-7939-1
USN-7939-2

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu