Clear wdev->cqm_config pointer on free to prevent double-free in Linux kernel
CVE-2024-50235

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
9 November 2024

What is CVE-2024-50235?

The Linux kernel has a vulnerability within the wifi configuration mechanism that concerns the cqm_config pointer. When unregistering a wireless device, the pointer is not being cleared, leading to the potential for double-free vulnerabilities during subsequent registrations in another network namespace. This flaw can occur if the same wdev/netdev structure is re-registered and then destroyed, which can lead to serious security implications if exploited.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux c797498e860e9a435a651bbf0789433684ce6dd8

Linux 37c20b2effe987b806c8de6d12978e4ffeff026f < 6c44abb2d4c3262737d5d67832daebc8cf48b8c9

Linux 37c20b2effe987b806c8de6d12978e4ffeff026f < 64e4c45d23cd7f6167f69cc2d2877bc7f54292e5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.