CVE-2024-49874·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: Fix use after free vulnerability in svc_i3c_master Driver Due to Race Condition In the svc_i3c_master_probe function, &master->hj_work is bound with svc_i3c_master_hj_work, &master->ibi_work is bound with svc_i3c_master_ibi_work. And svc_i3c_master_ibi_work can start the hj_work, svc_i3c_master_irq_handler can start the ibi_work. If we remove the module which will call svc_i3c_master_remove to make cleanup, it will free master->base through i3c_master_unregister while the work mentioned above will be used. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | svc_i3c_master_hj_work svc_i3c_master_remove | i3c_master_unregister(&master->base)| device_unregister(&master->dev) | device_release | //free master->base | | i3c_master_do_daa(&master->base) | //use master->base Fix it by ensuring that the work is canceled before proceeding with the cleanup in svc_i3c_master_remove.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.11.3
- Published
- 2024-10-21
Affected versions
From: 6.11
Until: 6.11.3
Fixed in: 6.11.3
How to fix this CVE
Update your Linux kernel to version 6.11.3 or later to resolve a use-after-free vulnerability in the i3c master svc driver. This vulnerability arises from a race condition between asynchronous work queue tasks and module removal, which can lead to kernel memory corruption. Kernel updates should be applied and the system rebooted to ensure the patched code is in use.
sudo dnf update kernel kernel-devel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check installed kernel version with 'uname -r' and compare against 6.11.3 (vulnerable if 6.11.0-6.11.2)
- Step 2: Verify i3c master svc driver is loaded via 'lsmod | grep i3c' to confirm the vulnerable component is present
- Step 3: Search system logs for use-after-free warnings related to i3c_master or svc_i3c_master using 'sudo dmesg | grep -i 'use.*after.*free\|UAF' and 'sudo journalctl -xe | grep -i i3c'
- Step 4: After applying the kernel update, verify the new version with 'uname -r' and confirm it shows 6.11.3 or later
FAQ
What is CVE-2024-49874?
CVE-2024-49874 is a use-after-free vulnerability in the Linux kernel's i3c master svc (Silvaco) driver caused by improper synchronization between work queue tasks and module removal, allowing freed kernel memory to be accessed during asynchronous operations.
Is CVE-2024-49874 being actively exploited?
No, this vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and no public exploits are currently available, though the high CVSS score of 7.0 warrants prompt patching.
What versions of Kernel are affected by CVE-2024-49874?
Linux kernel versions 6.11.0 through 6.11.2 are affected. The vulnerability is fixed in version 6.11.3 and later.
How do I check if my server is vulnerable to CVE-2024-49874?
Run 'uname -r' to display your kernel version. If the output shows 6.11.0, 6.11.1, or 6.11.2, your system is vulnerable and requires a kernel update.
Does Defensia detect CVE-2024-49874?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-49874 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/27b55724d3f781dd6e635e89dc6e2fd78fa81a00
- https://git.kernel.org/stable/c/4318998892bf8fe99f97bea18c37ae7b685af75a
- https://git.kernel.org/stable/c/4ac637122930cc4ab7e2c22e364cf3aaf96b05b1
- https://git.kernel.org/stable/c/56bddf543d4d7ddeff3f87b554ddacfdf086bffe
- https://git.kernel.org/stable/c/61850725779709369c7e907ae8c7c75dc7cec4f3
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-49874. Free for 1 server.
Get started free