CVE-2024-50112·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: x86/lam: Disable ADDRESS_MASKING in most cases Linear Address Masking (LAM) has a weakness related to transient execution as described in the SLAM paper[1]. Unless Linear Address Space Separation (LASS) is enabled this weakness may be exploitable. Until kernel adds support for LASS[2], only allow LAM for COMPILE_TEST, or when speculation mitigations have been disabled at compile time, otherwise keep LAM disabled. There are no processors in market that support LAM yet, so currently nobody is affected by this issue. [1] SLAM: https://download.vusec.net/papers/slam_sp24.pdf [2] LASS: https://lore.kernel.org/lkml/20230609183632.48706-1-alexander.shishkin@linux.intel.com/ [ dhansen: update SPECULATION_MITIGATIONS -> CPU_MITIGATIONS ]
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.11.6
- Published
- 2024-11-05
Affected versions
From: 6.7
Until: 6.11.6
Fixed in: 6.11.6
How to fix this CVE
Update your Linux kernel to version 6.11.6 or later to disable the vulnerable Linear Address Masking (LAM) feature until proper mitigations are in place. This patch restricts LAM usage to systems with speculation mitigations disabled or test builds, eliminating a transient execution side-channel weakness. Kernel updates should be applied and systems rebooted to take effect.
sudo dnf check-update kernel && sudo dnf update kernel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version with `uname -r` and verify it is 6.11.6 or later
- Step 2: Confirm LAM is disabled by checking `cat /proc/cmdline` for the absence of `lam=` parameters, or inspect kernel config with `cat /boot/config-$(uname -r) | grep CONFIG_ARCH_SUPPORTS_LINEAR_ADDRESS_MASKING`
- Step 3: Search system logs for LAM-related warnings with `sudo grep -i 'lam\|linear.*address' /var/log/kern.log /var/log/messages 2>/dev/null`
- Step 4: After patching, verify the kernel version again with `uname -r` to confirm 6.11.6+ is running, then run `sudo systemctl status` to ensure no pending reboot is required
FAQ
What is CVE-2024-50112?
CVE-2024-50112 is a transient execution vulnerability in Linux kernel's Linear Address Masking (LAM) feature that could be exploited via speculative execution side-channels when LASS (Linear Address Space Separation) is unavailable. The patch disables LAM by default to prevent exploitation until proper security isolation mechanisms are implemented.
Is CVE-2024-50112 being actively exploited?
No, CVE-2024-50112 is not actively exploited in the wild and there are no public exploits available. Additionally, no processors currently on the market support LAM, making practical exploitation impossible at this time.
What versions of Kernel are affected by CVE-2024-50112?
Linux kernel versions 6.7 through 6.11.5 are vulnerable. The fix is available in kernel 6.11.6 and later.
How do I check if my server is vulnerable to CVE-2024-50112?
Run `uname -r` to display your kernel version. If the output shows version 6.7 to 6.11.5, your system is vulnerable and requires a kernel update to 6.11.6 or later.
Does Defensia detect CVE-2024-50112?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-50112 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-50112. Free for 1 server.
Get started free