🛡️ AZL-53379 — kernel

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

CVE-2024-50261 affecting package kernel for versions less than 6.6.64.2-1

In the Linux kernel, the following vulnerability has been resolved:

macsec: Fix use-after-free while sending the offloading packet

KASAN reports the following UAF. The metadata_dst, which is used to

store the SCI value for macsec offload, is already freed by

metadata_dst_free() in macsec_free_netdev(), while driver still use it

for sending the packet.

To fix this issue, dst_release() is used instead to release

metadata_dst. So it is not freed instantly in macsec_free_netdev() if

still referenced by skb.

BUG: KASAN: slab-use-after-free in mlx5e_xmit+0x1e8f/0x4190 [mlx5_core]

Read of size 2 at addr ffff88813e42e038 by task kworker/7:2/714

[...]

Workqueue: mld mld_ifc_work

Call Trace:

<TASK>

dump_stack_lvl+0x51/0x60

print_report+0xc1/0x600

kasan_report+0xab/0xe0

mlx5e_xmit+0x1e8f/0x4190 [mlx5_core]

dev_hard_start_xmit+0x120/0x530

sch_direct_xmit+0x149/0x11e0

__qdisc_run+0x3ad/0x1730

__dev_queue_xmit+0x1196/0x2ed0

vlan_dev_hard_start_xmit+0x32e/0x510 [8021q]

dev_hard_start_xmit+0x120/0x530

__dev_queue_xmit+0x14a7/0x2ed0

macsec_start_xmit+0x13e9/0x2340

dev_hard_start_xmit+0x120/0x530

__dev_queue_xmit+0x14a7/0x2ed0

ip6_finish_output2+0x923/0x1a70

ip6_finish_output+0x2d7/0x970

ip6_output+0x1ce/0x3a0

NF_HOOK.constprop.0+0x15f/0x190

mld_sendpack+0x59a/0xbd0

mld_ifc_work+0x48a/0xa80

process_one_work+0x5aa/0xe50

worker_thread+0x79c/0x1290

kthread+0x28f/0x350

ret_from_fork+0x2d/0x70

ret_from_fork_asm+0x11/0x20

</TASK>

Allocated by task 3922:

kasan_save_stack+0x20/0x40

kasan_save_track+0x10/0x30

__kasan_kmalloc+0x77/0x90

__kmalloc_noprof+0x188/0x400

metadata_dst_alloc+0x1f/0x4e0

macsec_newlink+0x914/0x1410

__rtnl_newlink+0xe08/0x15b0

rtnl_newlink+0x5f/0x90

rtnetlink_rcv_msg+0x667/0xa80

netlink_rcv_skb+0x12c/0x360

netlink_unicast+0x551/0x770

netlink_sendmsg+0x72d/0xbd0

__sock_sendmsg+0xc5/0x190

____sys_sendmsg+0x52e/0x6a0

___sys_sendmsg+0xeb/0x170

__sys_sendmsg+0xb5/0x140

do_syscall_64+0x4c/0x100

entry_SYSCALL_64_after_hwframe+0x4b/0x53

Freed by task 4011:

kasan_save_stack+0x20/0x40

kasan_save_track+0x10/0x30

kasan_save_free_info+0x37/0x50

poison_slab_object+0x10c/0x190

__kasan_slab_free+0x11/0x30

kfree+0xe0/0x290

macsec_free_netdev+0x3f/0x140

netdev_run_todo+0x450/0xc70

rtnetlink_rcv_msg+0x66f/0xa80

netlink_rcv_skb+0x12c/0x360

netlink_unicast+0x551/0x770

netlink_sendmsg+0x72d/0xbd0

__sock_sendmsg+0xc5/0x190

____sys_sendmsg+0x52e/0x6a0

___sys_sendmsg+0xeb/0x170

__sys_sendmsg+0xb5/0x140

do_syscall_64+0x4c/0x100

entry_SYSCALL_64_after_hwframe+0x4b/0x53

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.

Affected software

AZL-53379 is recorded against 1 package.

  • kernel (fixed in 6.6.64.2-1)

Timeline and source

Published on 9 November 2024 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

nvd.nist.gov (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-11-09
Updated 2026-08-12
Modified 2026-04-21
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 6.6.64.2-1

Similar Threats

Free Vulnerability Check

Is your site affected by AZL-53379?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-53379 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.