🛡️ CVE-2024-50276 — kernel

🔴 CVSS 9.8 — Critical ✅ No Known Exploit NVD
9.8
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

net: vertexcom: mse102x: Fix possible double free of TX skb

In the Linux kernel, the following vulnerability has been resolved:

net: vertexcom: mse102x: Fix possible double free of TX skb

The scope of the TX skb is wider than just mse102x_tx_frame_spi(),

so in case the TX skb room needs to be expanded, we should free the

the temporary skb instead of the original skb. Otherwise the original

TX skb pointer would be freed again in mse102x_tx_work(), which leads

to crashes:

Internal error: Oops: 0000000096000004 [#2] PREEMPT SMP

CPU: 0 PID: 712 Comm: kworker/0:1 Tainted: G D 6.6.23

Hardware name: chargebyte Charge SOM DC-ONE (DT)

Workqueue: events mse102x_tx_work [mse102x]

pstate: 20400009 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)

pc : skb_release_data+0xb8/0x1d8

lr : skb_release_data+0x1ac/0x1d8

sp : ffff8000819a3cc0

x29: ffff8000819a3cc0 x28: ffff0000046daa60 x27: ffff0000057f2dc0

x26: ffff000005386c00 x25: 0000000000000002 x24: 00000000ffffffff

x23: 0000000000000000 x22: 0000000000000001 x21: ffff0000057f2e50

x20: 0000000000000006 x19: 0000000000000000 x18: ffff00003fdacfcc

x17: e69ad452d0c49def x16: 84a005feff870102 x15: 0000000000000000

x14: 000000000000024a x13: 0000000000000002 x12: 0000000000000000

x11: 0000000000000400 x10: 0000000000000930 x9 : ffff00003fd913e8

x8 : fffffc00001bc008

x7 : 0000000000000000 x6 : 0000000000000008

x5 : ffff00003fd91340 x4 : 0000000000000000 x3 : 0000000000000009

x2 : 00000000fffffffe x1 : 0000000000000000 x0 : 0000000000000000

Call trace:

skb_release_data+0xb8/0x1d8

kfree_skb_reason+0x48/0xb0

mse102x_tx_work+0x164/0x35c [mse102x]

process_one_work+0x138/0x260

worker_thread+0x32c/0x438

kthread+0x118/0x11c

ret_from_fork+0x10/0x20

Code: aa1303e0 97fffab6 72001c1f 54000141 (f9400660)

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.

Affected software

CVE-2024-50276 is recorded against 2 packages.

  • kernel (from 6.7.0 up to 6.11.8)
  • linux-kernel

Timeline and source

Published on 19 November 2024 and last revised on 6 August 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
lists.debian.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2024-50276 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Critical
CVSS Score 9.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2024-11-19
Updated 2026-08-12
Modified 2026-08-06

Affected Packages

Software From version Fixed in
kernel 6.7.0 6.11.8
linux-kernel

Similar Threats

Exploit Protection

Are you running kernel?

CVE-2024-50276 carries CVSS 9.8 Critical rating. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2024-50276 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2024