CVE-2024-49924·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: fbdev: pxafb: Fix possible use after free in pxafb_task() In the pxafb_probe function, it calls the pxafb_init_fbinfo function, after which &fbi->task is associated with pxafb_task. Moreover, within this pxafb_init_fbinfo function, the pxafb_blank function within the &pxafb_ops struct is capable of scheduling work. If we remove the module which will call pxafb_remove to make cleanup, it will call unregister_framebuffer function which can call do_unregister_framebuffer to free fbi->fb through put_fb_info(fb_info), while the work mentioned above will be used. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | pxafb_task pxafb_remove | unregister_framebuffer(info) | do_unregister_framebuffer(fb_info) | put_fb_info(fb_info) | // free fbi->fb | set_ctrlr_state(fbi, state) | __pxafb_lcd_power(fbi, 0) | fbi->lcd_power(on, &fbi->fb.var) | //use fbi->fb Fix it by ensuring that the work is canceled before proceeding with the cleanup in pxafb_remove. Note that only root user can remove the driver at runtime.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.11.3
- Published
- 2024-10-21
Affected versions
From: 6.11
Until: 6.11.3
Fixed in: 6.11.3
How to fix this CVE
Update your Linux kernel to version 6.11.3 or later to patch a use-after-free vulnerability in the PXA framebuffer driver. The vulnerability occurs when kernel module removal races with pending framebuffer tasks, potentially allowing memory corruption. Prioritize this update for systems running kernel versions 6.11.0 through 6.11.2, especially those with PXA display hardware or framebuffer drivers loaded.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check kernel version with `uname -r` — vulnerable if output shows 6.11.0, 6.11.1, or 6.11.2
- Step 2: Verify if PXA framebuffer driver is loaded with `lsmod | grep pxafb` or `grep -i pxafb /proc/modules`
- Step 3: Search kernel logs for framebuffer-related crashes: `dmesg | grep -iE '(pxafb|framebuffer|use.after.free|UAF)'` or `journalctl -k | grep -iE '(pxafb|use.after.free)'`
- Step 4: After patching, verify new kernel version with `uname -r` — should show 6.11.3 or higher
FAQ
What is CVE-2024-49924?
CVE-2024-49924 is a use-after-free vulnerability in the Linux kernel's PXA framebuffer driver where pending work tasks access freed memory structures during module removal, potentially allowing privilege escalation or denial of service.
Is CVE-2024-49924 being actively exploited?
No, CVE-2024-49924 is not listed in the CISA Known Exploited Vulnerabilities catalog and has no publicly available exploits, though exploitation requires root privileges to unload the driver.
What versions of Kernel are affected by CVE-2024-49924?
Linux kernel versions 6.11.0, 6.11.1, and 6.11.2 are vulnerable; the fix is included in kernel 6.11.3 and later stable releases.
How do I check if my server is vulnerable to CVE-2024-49924?
Run `uname -r` and check if the output matches 6.11.0-6.11.2; additionally run `lsmod | grep pxafb` to confirm the vulnerable framebuffer driver is loaded on your system.
Does Defensia detect CVE-2024-49924?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2024-49924 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/3c0d416eb4bef705f699213cee94bf54b6acdacd
- https://git.kernel.org/stable/c/4a6921095eb04a900e0000da83d9475eb958e61e
- https://git.kernel.org/stable/c/4cda484e584be34d55ee17436ebf7ad11922b97a
- https://git.kernel.org/stable/c/6d0a07f68b66269e167def6c0b90a219cd3e7473
- https://git.kernel.org/stable/c/a3a855764dbacbdb1cc51e15dc588f2d21c93e0e
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-49924. Free for 1 server.
Get started free