CVE-2024-50085
A critical flaw in the Linux kernel's MPTCP module lets an attacker read memory that has already been freed, which can crash the system or lead to other problems. The bug was found by the Syzkaller fuzzing tool and has been fixed in recent kernel releases. Updating to a patched kernel version resolves the issue.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel 6.12 and earlier versions that contain the vulnerable MPTCP code. System administrators and users running Linux systems with MPTCP support are affected.
Real-world impact
An attacker could cause a kernel crash or potentially gain elevated privileges by reading freed memory, leading to denial of service or other malicious actions.
Why this severity
The CVSS score of 9.8 reflects that the flaw allows unauthenticated memory reads without user interaction, with a high impact on confidentiality, integrity, and availability.
What to do about it
- 01Upgrade your Linux kernel to version 6.12 or later.
- 02Reboot the system to load the new kernel.
NVD-referenced vendor advisory
Timeline
- Oct 29, 2024 · Oct 29, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.