CVE-2024-50302

medium KEV
Published 2025-03-11 · Modified 2025-03-14
CVSS v3
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2
VIR risk
7.0

Description

Important: kernel security update

CISA KEV

Vendor
Linux
Product
Kernel
Due date
2025-03-25

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2025-2627.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2329924

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2329370

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2327168

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2268295

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2025-2474.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2025:2474

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2025-2473.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2348562

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2337098

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2334412

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2327169

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2025:2473

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://lore.kernel.org/linux-cve-announce/2024111908-CVE-2024-50302-f677@gregkh/ ; https://source.android.com/docs/security/bulletin/2025-03-01 ; https://nvd.nist.gov/vuln/detail/CVE-2024-50302

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-50302

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2024-50302.html

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:2473

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:2474

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552

vendor Authored 2026-05-27

Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2025:2627

Exploits

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
suse slesaffected
debian debianbookwormfixed6.1.119-1
debian debianbullseyefixed5.10.234-1
debian debianforkyfixed6.11.9-1
debian debiansidfixed6.11.9-1
debian debiantrixiefixed6.11.9-1
linux linux-kernelaffected4.19.324
linux linux-kernel6.12affected
debian debian11.0affected

References

CWEs

CWE-908

Verify integrity in audit chain (admin only). AS-IS.