CVE-2024-49571
A critical flaw in the Linux kernel’s Secure Management Channel (SMC) handling can cause a crash when a malicious client sends a specially crafted proposal message. The bug allows an attacker to trigger a denial of service by sending values that exceed expected limits. The issue has been fixed in recent kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, especially versions before 6.13, used in servers and devices that support the Secure Management Channel (SMC).
Real-world impact
An attacker could crash the kernel, causing a denial of service on the affected system. This could lead to service interruption or require a reboot.
Why this severity
The CVSS score of 9.1 reflects that the flaw can be exploited remotely without authentication and can completely disrupt availability by crashing the kernel. The lack of required privileges and the high impact on availability drive the high score.
What to do about it
- 01Upgrade the Linux kernel to version 6.13 or later.
- 02Reboot the system to load the updated kernel.
NVD description indicates patch
Timeline
- Jan 11, 2025 · Jan 11, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/47ce46349672a7e0c3…patch
- git.kernel.org/stable/c/62056d1592e63d85e8…patch
- git.kernel.org/stable/c/846bada23bfcdeb836…patch
- git.kernel.org/stable/c/91a7c27c1444ed4677…patch
- git.kernel.org/stable/c/a29e220d3c8edbf0e1…patch
- git.kernel.org/stable/c/f10635268a0a49ee90…patch
- lists.debian.org/debian-lts-announce/2025/03…