{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-50024",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-10-21T12:17:06.065Z",
        "datePublished": "2024-10-21T19:39:29.203Z",
        "dateUpdated": "2026-08-05T11:41:02.236Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:41:02.236Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Fix an unsafe loop on the list\n\nThe kernel may crash when deleting a genetlink family if there are still\nlisteners for that family:\n\nOops: Kernel access of bad area, sig: 11 [#1]\n  ...\n  NIP [c000000000c080bc] netlink_update_socket_mc+0x3c/0xc0\n  LR [c000000000c0f764] __netlink_clear_multicast_users+0x74/0xc0\n  Call Trace:\n__netlink_clear_multicast_users+0x74/0xc0\ngenl_unregister_family+0xd4/0x2d0\n\nChange the unsafe loop on the list to a safe one, because inside the\nloop there is an element removal from this list."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The attacker-controlled state is built exclusively through local AF_NETLINK/NETLINK_GENERIC sockets (bind() and setsockopt(NETLINK_ADD_MEMBERSHIP)), and the faulty loop lives in netlink table maintenance code. There is no remote, adjacent-network, or guest-to-host path into `__netlink_clear_multicast_users()`.\nAC:L - The attacker deterministically constructs the dangerous `mc_list` — many sockets subscribed to many genl multicast group ids, with subscription counts arranged so the loop body unlinks the element it is standing on — and no condition outside their influence (specific timing window, unpredictable memory layout, or victim process state) is needed for the walk to leave the list.\nPR:L - NETLINK_GENERIC is registered with NL_CFG_F_NONROOT_RECV, so `netlink_allowed()` lets any unprivileged user join genl multicast groups, and `genl_bind()`'s CAP_NET_ADMIN/CAP_SYS_ADMIN checks are `ns_capable(net->user_ns, …)`, which a plain user satisfies via `unshare -Urn`; since `nl_table[].mc_list` is global and `genl_unregister_mc_groups()` sweeps every netns, sockets planted from an unprivileged namespace are walked by the buggy loop.\nUI:R - The unsafe loop only executes from `genl_unregister_family()`, which every in-tree caller reaches from a module exit or module-init failure path, so an administrator must unload/teardown the genl-providing module (rmmod, driver upgrade, udev-driven `modprobe -r`) after the attacker has planted the listeners.\nS:U - The stale list node, the netlink socket group bitmaps, and the corrupted slab memory all belong to the host kernel, the same security authority that is compromised. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The loop dereferences a list element already unlinked inside the body and reads through pointers taken from it (`test_bit(group - 1, nlk->groups)`), and the missing `ngroups` bound check — present in the sibling `netlink_update_listeners()` — makes that an out-of-bounds slab read at an attacker-chosen group index, a stale-object read primitive usable to disclose adjacent kernel heap contents.\nI:H - The same code path writes through the stale/undersized object — `__assign_bit(group - 1, nlk->groups, new)` and `nlk->subscriptions = subscriptions` — so once the freed or overrun slab region is groomed by the attacker this becomes an arbitrary-bit clear at an attacker-influenced address, plus corruption of the `mc_list` linkage itself, which is sufficient for control-flow hijacking.\nA:H - The committed reproduction is a hard kernel crash — \"Oops: Kernel access of bad area, sig: 11\" at `netlink_update_socket_mc+0x3c` under `__netlink_clear_multicast_users()` — and the corruption happens while `nl_table_lock` is held via `netlink_table_grab()` (`write_lock_irq`), so a mangled list also wedges the entire netlink subsystem."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "include/net/sock.h",
                        "net/netlink/af_netlink.c"
                    ],
                    "versions": [
                        {
                            "version": "b8273570f802a7658827dcb077b0b517ba75a289",
                            "lessThan": "464801a0f6ccb52b21faa33bac6014fd74cc5e10",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "b8273570f802a7658827dcb077b0b517ba75a289",
                            "lessThan": "8e0766fcf37ad8eed289dd3853628dd9b01b58b0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "b8273570f802a7658827dcb077b0b517ba75a289",
                            "lessThan": "68ad5da6ca630a276f0a5c924179e57724d00013",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "b8273570f802a7658827dcb077b0b517ba75a289",
                            "lessThan": "1cdec792b2450105b1314c5123a9a0452cb2c2f0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "b8273570f802a7658827dcb077b0b517ba75a289",
                            "lessThan": "5f03a7f601f33cda1f710611625235dc86fd8a9e",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "b8273570f802a7658827dcb077b0b517ba75a289",
                            "lessThan": "3be342e0332a7c83eb26fbb22bf156fdca467a5d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "b8273570f802a7658827dcb077b0b517ba75a289",
                            "lessThan": "49f9b726bf2bf3dd2caf0d27cadf4bc1ccf7a7dd",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "b8273570f802a7658827dcb077b0b517ba75a289",
                            "lessThan": "1dae9f1187189bc09ff6d25ca97ead711f7e26f9",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "include/net/sock.h",
                        "net/netlink/af_netlink.c"
                    ],
                    "versions": [
                        {
                            "version": "2.6.32",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "2.6.32",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "4.19.323",
                            "lessThanOrEqual": "4.19.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.4.285",
                            "lessThanOrEqual": "5.4.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.227",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.168",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.113",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.57",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.11.4",
                            "lessThanOrEqual": "6.11.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "4.19.323"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "5.4.285"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "5.10.227"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "5.15.168"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "6.1.113"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "6.6.57"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "6.11.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "6.12"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/464801a0f6ccb52b21faa33bac6014fd74cc5e10"
                },
                {
                    "url": "https://git.kernel.org/stable/c/8e0766fcf37ad8eed289dd3853628dd9b01b58b0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/68ad5da6ca630a276f0a5c924179e57724d00013"
                },
                {
                    "url": "https://git.kernel.org/stable/c/1cdec792b2450105b1314c5123a9a0452cb2c2f0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/5f03a7f601f33cda1f710611625235dc86fd8a9e"
                },
                {
                    "url": "https://git.kernel.org/stable/c/3be342e0332a7c83eb26fbb22bf156fdca467a5d"
                },
                {
                    "url": "https://git.kernel.org/stable/c/49f9b726bf2bf3dd2caf0d27cadf4bc1ccf7a7dd"
                },
                {
                    "url": "https://git.kernel.org/stable/c/1dae9f1187189bc09ff6d25ca97ead711f7e26f9"
                }
            ],
            "title": "net: Fix an unsafe loop on the list",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2024-50024",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2024-10-22T13:27:00.388543Z"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-10-22T13:28:46.817Z"
                }
            },
            {
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
                    },
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
                    }
                ],
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2025-11-03T22:24:35.047Z"
                }
            }
        ]
    }
}