🛡️ CVE-2024-50257 — kernel

🟠 CVSS 7.0 — High ✅ No Known Exploit NVD
7.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

netfilter: Fix use-after-free in get_info()

In the Linux kernel, the following vulnerability has been resolved:

netfilter: Fix use-after-free in get_info()

ip6table_nat module unload has refcnt warning for UAF. call trace is:

WARNING: CPU: 1 PID: 379 at kernel/module/main.c:853 module_put+0x6f/0x80

Modules linked in: ip6table_nat(-)

CPU: 1 UID: 0 PID: 379 Comm: ip6tables Not tainted 6.12.0-rc4-00047-gc2ee9f594da8-dirty #205

Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),

BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014

RIP: 0010:module_put+0x6f/0x80

Call Trace:

<TASK>

get_info+0x128/0x180

do_ip6t_get_ctl+0x6a/0x430

nf_getsockopt+0x46/0x80

ipv6_getsockopt+0xb9/0x100

rawv6_getsockopt+0x42/0x190

do_sock_getsockopt+0xaa/0x180

__sys_getsockopt+0x70/0xc0

__x64_sys_getsockopt+0x20/0x30

do_syscall_64+0xa2/0x1a0

entry_SYSCALL_64_after_hwframe+0x77/0x7f

Concurrent execution of module unload and get_info() trigered the warning.

The root cause is as follows:

cpu0 cpu1

module_exit

//mod->state = MODULE_STATE_GOING

ip6table_nat_exit

xt_unregister_template

kfree(t)

//removed from templ_list

getinfo()

t = xt_find_table_lock

list_for_each_entry(tmpl, &xt_templates[af]...)

if (strcmp(tmpl->name, name))

continue; //table not found

try_module_get

list_for_each_entry(t, &xt_net->tables[af]...)

return t; //not get refcnt

module_put(t->me) //uaf

unregister_pernet_subsys

//remove table from xt_net list

While xt_table module was going away and has been removed from

xt_templates list, we couldnt get refcnt of xt_table->me. Check

module in xt_net->tables list re-traversal to fix it.

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is high, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.

Affected software

CVE-2024-50257 is recorded against 2 packages.

  • kernel (from 6.7.0 up to 6.11.7)
  • linux-kernel

Timeline and source

Published on 9 November 2024 and last revised on 6 August 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
lists.debian.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2024-50257 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity High
CVSS Score 7.0
CVSS Vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2024-11-09
Updated 2026-08-12
Modified 2026-08-06

Affected Packages

Software From version Fixed in
kernel 6.7.0 6.11.7
linux-kernel

Similar Threats

Site Security Check

Is kernel part of your stack?

CVE-2024-50257 is rated CVSS 7.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.