CVE-2024-50235
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-50235 is a vulnerability affecting the Linux kernel. This issue involves the wifi driver, specifically the cfg80211 subsystem. When freeing the memory allocated to wdev->cqm_config during device unregistration, the kernel failed to clear the pointer. Consequently, if the same wdev/netdev is later re-registered in another network namespace and destroyed, the code would run again, resulting in a double-free condition. This vulnerability could potentially lead to memory corruption and related security risks. The vulnerability has been addressed in recent Linux kernel updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX