CVE-2024-49982·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: aoe: fix the potential use-after-free problem in more places For fixing CVE-2023-6270, f98364e92662 ("aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts") makes tx() calling dev_put() instead of doing in aoecmd_cfg_pkts(). It avoids that the tx() runs into use-after-free. Then Nicolai Stange found more places in aoe have potential use-after-free problem with tx(). e.g. revalidate(), aoecmd_ata_rw(), resend(), probe() and aoecmd_cfg_rsp(). Those functions also use aoenet_xmit() to push packet to tx queue. So they should also use dev_hold() to increase the refcnt of skb->dev. On the other hand, moving dev_put() to tx() causes that the refcnt of skb->dev be reduced to a negative value, because corresponding dev_hold() are not called in revalidate(), aoecmd_ata_rw(), resend(), probe(), and aoecmd_cfg_rsp(). This patch fixed this issue.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.11.3
- Published
- 2024-10-21
Affected versions
From: 6.11
Until: 6.11.3
Fixed in: 6.11.3
How to fix this CVE
Update your Linux kernel to version 6.11.3 or later to resolve a use-after-free vulnerability in the AoE (ATA over Ethernet) subsystem. The vulnerability affects multiple functions that transmit network packets without properly managing device reference counts, potentially leading to memory corruption. Apply the kernel update and reboot your system to activate the security fix.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your kernel version with `uname -r` and compare against the affected range (6.11.0 through 6.11.3)
- Step 2: Verify AoE support is loaded by running `lsmod | grep aoe` — if no output, AoE is not loaded and risk is minimal
- Step 3: Check system logs for memory corruption errors or kernel panics related to AoE with `sudo dmesg | grep -i 'aoe\|use-after-free'`
- Step 4: After updating the kernel, run `uname -r` to confirm version 6.11.3 or higher is active, and reboot if needed
FAQ
What is CVE-2024-49982?
CVE-2024-49982 is a use-after-free vulnerability in the Linux kernel's ATA over Ethernet (AoE) driver where multiple functions fail to properly manage device reference counts during packet transmission, allowing potential memory corruption and privilege escalation.
Is CVE-2024-49982 being actively exploited?
No, this vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog and no public exploits are currently available, though it remains a high-severity local attack vector.
What versions of Kernel are affected by CVE-2024-49982?
Linux kernel versions 6.11.0 through 6.11.3 are affected; the vulnerability was introduced by an incomplete fix to CVE-2023-6270 and is resolved in kernel 6.11.3 and later.
How do I check if my server is vulnerable to CVE-2024-49982?
Run `uname -r` to get your kernel version and verify it falls within 6.11.0–6.11.2; additionally check `lsmod | grep aoe` to confirm the AoE module is loaded on your system.
Does Defensia detect CVE-2024-49982?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-49982 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/07b418d50ccbbca7e5d87a3a0d41d436cefebf79
- https://git.kernel.org/stable/c/12f7b89dd72b25da4eeaa22097877963cad6418e
- https://git.kernel.org/stable/c/6d6e54fc71ad1ab0a87047fd9c211e75d86084a3
- https://git.kernel.org/stable/c/8253a60c89ec35c8f36fb2cc08cdf854c7a3eb58
- https://git.kernel.org/stable/c/89d9a69ae0c667e4d9d028028e2dcc837bae626f
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-49982. Free for 1 server.
Get started free