cve/2024/CVE-2024-50036.md

24 lines
2.0 KiB
Markdown
Raw Normal View History

2025-09-29 21:09:30 +02:00
### [CVE-2024-50036](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50036)
![](https://img.shields.io/static/v1?label=Product&message=Linux&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=3.16%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=591b1e1bb40152e22cee757f493046a0ca946bf8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=86e48c03d774e01ccd71ecba4fc4b5c2bc0b5b41%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=9a4fe697023dbe6c25caa1f8b2153af869a29bd2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=df90819dafcd6b97fc665f63a15752a570e227a2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=f88649721268999bdff09777847080a52004f691%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=blue)
### Description
In the Linux kernel, the following vulnerability has been resolved:net: do not delay dst_entries_add() in dst_release()dst_entries_add() uses per-cpu data that might be freed at netnsdismantle from ip6_route_net_exit() calling dst_entries_destroy()Before ip6_route_net_exit() can be called, we release allthe dsts associated with this netns, via calls to dst_release(),which waits an rcu grace period before calling dst_destroy()dst_entries_add() use in dst_destroy() is racy, becausedst_entries_destroy() could have been called already.Decrementing the number of dsts must happen sooner.Notes:1) in CONFIG_XFRM case, dst_destroy() can call dst_release_immediate(child), this might also cause UAF if the child does not have DST_NOCOUNT set. IPSEC maintainers might take a look and see how to address this.2) There is also discussion about removing this count of dst, which might happen in future kernels.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/w4zu/Debian_security