CVE-2024-50227·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix KASAN reported stack out-of-bounds read in tb_retimer_scan() KASAN reported following issue: BUG: KASAN: stack-out-of-bounds in tb_retimer_scan+0xffe/0x1550 [thunderbolt] Read of size 4 at addr ffff88810111fc1c by task kworker/u56:0/11 CPU: 0 UID: 0 PID: 11 Comm: kworker/u56:0 Tainted: G U 6.11.0+ #1387 Tainted: [U]=USER Workqueue: thunderbolt0 tb_handle_hotplug [thunderbolt] Call Trace: <TASK> dump_stack_lvl+0x6c/0x90 print_report+0xd1/0x630 kasan_report+0xdb/0x110 __asan_report_load4_noabort+0x14/0x20 tb_retimer_scan+0xffe/0x1550 [thunderbolt] tb_scan_port+0xa6f/0x2060 [thunderbolt] tb_handle_hotplug+0x17b1/0x3080 [thunderbolt] process_one_work+0x626/0x1100 worker_thread+0x6c8/0xfa0 kthread+0x2c8/0x3a0 ret_from_fork+0x3a/0x80 ret_from_fork_asm+0x1a/0x30 This happens because the loop variable still gets incremented by one so max becomes 3 instead of 2, and this makes the second loop read past the the array declared on the stack. Fix this by assigning to max directly in the loop body.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.11.7
- Published
- 2024-11-09
Affected versions
From: 6.11
Until: 6.11.7
Fixed in: 6.11.7
How to fix this CVE
Update your Linux kernel to version 6.11.7 or later to resolve a memory safety issue in the Thunderbolt subsystem. This vulnerability affects kernel versions 6.11 through 6.11.6 and causes a stack buffer read vulnerability during Thunderbolt device enumeration. Apply the kernel update through your distribution's package manager and reboot to complete the remediation.
sudo dnf upgrade kernel kernel-headers kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check your current kernel version with: uname -r | awk -F. '{print $1"."$2"."$3}'
- Verify if Thunderbolt is enabled in your system: lsmod | grep thunderbolt (if output appears, Thunderbolt module is loaded)
- Search dmesg logs for KASAN warnings related to tb_retimer_scan: sudo dmesg | grep -i 'kasan\|tb_retimer_scan\|stack-out-of-bounds'
- Confirm the patch is applied by checking if kernel version is 6.11.7 or higher: uname -r
FAQ
What is CVE-2024-50227?
CVE-2024-50227 is a stack buffer over-read vulnerability in the Linux kernel's Thunderbolt driver subsystem. During Thunderbolt device enumeration, an improper loop variable increment causes the kernel to read beyond allocated stack memory, potentially leading to information disclosure or kernel panic.
Is CVE-2024-50227 being actively exploited?
No, CVE-2024-50227 is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are currently available. However, it remains a high-severity local vulnerability requiring prompt patching.
What versions of Kernel are affected by CVE-2024-50227?
Linux kernel versions 6.11 through 6.11.6 are affected. The vulnerability was resolved in kernel 6.11.7 and later.
How do I check if my server is vulnerable to CVE-2024-50227?
Run 'uname -r' to check your kernel version. If the output shows 6.11.x where x is less than 7 (e.g., 6.11.0 through 6.11.6), your system is vulnerable.
Does Defensia detect CVE-2024-50227?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server running version 6.11.0 through 6.11.6, CVE-2024-50227 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-50227. Free for 1 server.
Get started free