CVE-2024-49568
A critical flaw in the Linux kernel's SMC handling could let a remote attacker crash the system by sending a specially crafted proposal message. The kernel did not validate certain fields, allowing out‑of‑bounds memory access. The issue has been fixed by adding checks before using those fields.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, including version 6.13 and earlier, on any system that uses the SMC protocol.
Real-world impact
An attacker could crash the system, causing a denial of service, and potentially gain higher privileges or steal data by exploiting the vulnerability.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited remotely without authentication and can completely compromise confidentiality, integrity, and availability of the system.
What to do about it
- 011. Update the Linux kernel to the latest available version that includes the fix.
- 022. Reboot the system to load the new kernel.
NVD patch description
Timeline
- Jan 11, 2025 · Jan 11, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.