CVE-2024-50059·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: ntb: ntb_hw_switchtec: Fix use after free vulnerability in switchtec_ntb_remove due to race condition In the switchtec_ntb_add function, it can call switchtec_ntb_init_sndev function, then &sndev->check_link_status_work is bound with check_link_status_work. switchtec_ntb_link_notification may be called to start the work. If we remove the module which will call switchtec_ntb_remove to make cleanup, it will free sndev through kfree(sndev), while the work mentioned above will be used. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | check_link_status_work switchtec_ntb_remove | kfree(sndev); | | if (sndev->link_force_down) | // use sndev Fix it by ensuring that the work is canceled before proceeding with the cleanup in switchtec_ntb_remove.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.11.4
- Published
- 2024-10-21
Affected versions
From: 6.7
Until: 6.11.4
Fixed in: 6.11.4
How to fix this CVE
Update your Linux kernel to version 6.11.4 or later to resolve a use-after-free vulnerability in the NTB Switchtec driver that can occur when the kernel module is removed while background link-status checks are still running. This race condition allows freed memory to be accessed by a scheduled work queue, potentially causing system instability or information disclosure. Apply the kernel update through your distribution's package manager and reboot your system to activate the patched kernel.
sudo dnf update kernel kernel-devel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version by running `uname -r` and compare against the affected range (6.7 to 6.11.3)
- Step 2: Verify if the Switchtec NTB driver is loaded by executing `lsmod | grep switchtec_ntb` — if output appears, the vulnerable component is present
- Step 3: Search system logs for UAF-related kernel warnings using `sudo dmesg | grep -i 'use-after-free\|UAF\|bad-access'` or check `/var/log/kern.log`
- Step 4: After patching, confirm the new kernel is active with `uname -r` showing version 6.11.4 or later, and verify the module reloads cleanly by unloading and reloading it: `sudo modprobe -r switchtec_ntb && sudo modprobe switchtec_ntb`
FAQ
What is CVE-2024-50059?
CVE-2024-50059 is a use-after-free vulnerability in the Linux kernel's NTB Switchtec driver where the kernel module frees driver memory while a background work queue is still scheduled to access it, creating a race condition that can cause memory corruption or system crashes.
Is CVE-2024-50059 being actively exploited?
No, CVE-2024-50059 is not listed as actively exploited in the CISA Known Exploited Vulnerabilities catalog, and no public exploits have been disclosed.
What versions of Kernel are affected by CVE-2024-50059?
Linux kernel versions 6.7 through 6.11.3 are vulnerable; version 6.11.4 and later contain the fix.
How do I check if my server is vulnerable to CVE-2024-50059?
Run `uname -r` to check your kernel version — if it shows 6.7.x through 6.11.3, you are vulnerable. Additionally, confirm the Switchtec NTB driver is in use with `lsmod | grep switchtec_ntb`.
Does Defensia detect CVE-2024-50059?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-50059 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/177925d9c8715a897bb79eca62628862213ba956
- https://git.kernel.org/stable/c/3ae45be8492460a35b5aebf6acac1f1d32708946
- https://git.kernel.org/stable/c/5126d8f5567f49b52e21fca320eaa97977055099
- https://git.kernel.org/stable/c/92728fceefdaa2a0a3aae675f86193b006eeaa43
- https://git.kernel.org/stable/c/b650189687822b705711f0567a65a164a314d8df
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-50059. Free for 1 server.
Get started free