CVE-2024-46831·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap: Fix use-after-free error in kunit test This is a clear use-after-free error. We remove it, and rely on checking the return code of vcap_del_rule.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.10.10
- Published
- 2024-09-27
Affected versions
From: 6.7
Until: 6.10.10
Fixed in: 6.10.10
How to fix this CVE
Update your Linux kernel to version 6.10.10 or later to patch a use-after-free vulnerability in the Microchip VCAP driver's kunit test module. This memory safety issue could allow local attackers with low privileges to cause a denial of service or potentially escalate privileges. Systems running affected kernel versions 6.7 through 6.10.9 should prioritize this update.
sudo dnf update kernel kernel-devel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Check your installed kernel version by running: uname -r
- Verify if Microchip VCAP driver is loaded: lsmod | grep vcap
- Search kernel logs for memory corruption indicators: sudo dmesg | grep -i 'use-after-free\|memory\|fault'
- Confirm the fix by verifying the kernel version is 6.10.10 or later: uname -r | grep -E '6\.(10\.[1-9][0-9]|1[1-9]|[2-9][0-9])'
- Review system logs for crashes in vcap test module: sudo grep -i 'vcap\|kunit' /var/log/kern.log
FAQ
What is CVE-2024-46831?
CVE-2024-46831 is a use-after-free memory vulnerability in the Microchip VCAP (VCAT and Policer) driver's kernel unit test implementation, affecting Linux kernel versions 6.7 through 6.10.9. This flaw occurs in the kunit test module when memory is accessed after it has been freed, potentially leading to system instability or privilege escalation.
Is CVE-2024-46831 being actively exploited?
No, CVE-2024-46831 is not listed as actively exploited in the CISA Known Exploited Vulnerabilities catalog, and no public exploits are currently available. However, the vulnerability still poses a risk to systems running the affected kernel versions.
What versions of Kernel are affected by CVE-2024-46831?
Linux kernel versions 6.7 through 6.10.9 are vulnerable to CVE-2024-46831. The vulnerability was fixed in kernel version 6.10.10 and later releases.
How do I check if my server is vulnerable to CVE-2024-46831?
Run 'uname -r' to check your kernel version. If the output shows a version between 6.7 and 6.10.9, your system is vulnerable. Additionally, check if the Microchip VCAP driver is present by running 'lsmod | grep vcap'.
Does Defensia detect CVE-2024-46831?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-46831 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-46831. Free for 1 server.
Get started free