Answer in brief
CVE-2024-50036 records a Unknown severity vulnerability in net: do not delay dst_entries_add() in dst_release(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-50036 records a Unknown severity vulnerability in net: do not delay dst_entries_add() in dst_release(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f88649721268999bdff09777847080a52004f691 <547087307bc19417b4f2bc85ba9664a3e8db5a6a || >=f88649721268999bdff09777847080a52004f691 <e3915f028b1f1c37e87542e5aadd33728c259d96 || >=f88649721268999bdff09777847080a52004f691 <a60db84f772fc3a906c6c4072f9207579c41166f || >=f88649721268999bdff09777847080a52004f691 <eae7435b48ffc8e9be0ff9cfeae40af479a609dd || >=f88649721268999bdff09777847080a52004f691 <3c7c918ec0aa3555372c5a57f18780b7a96c5cfc || >=f88649721268999bdff09777847080a52004f691 <ac888d58869bb99753e7652be19a151df9ecb35d || 86e48c03d774e01ccd71ecba4fc4b5c2bc0b5b41 || 591b1e1bb40152e22cee757f493046a0ca946bf8 || df90819dafcd6b97fc665f63a15752a570e227a2 || 9a4fe697023dbe6c25caa1f8b2153af869a29bd2 || >=3.10.50 <3.11 || >=3.12.26 <3.13 || >=3.14.14 <3.15 || >=3.15.7 <3.16 | 547087307bc19417b4f2bc85ba9664a3e8db5a6a, e3915f028b1f1c37e87542e5aadd33728c259d96, a60db84f772fc3a906c6c4072f9207579c41166f, eae7435b48ffc8e9be0ff9cfeae40af479a609dd, 3c7c918ec0aa3555372c5a57f18780b7a96c5cfc, ac888d58869bb99753e7652be19a151df9ecb35d, 3.11, 3.13, 3.15, 3.16 |
| Linux/Linuxgeneric | 3.16 | Not reported |
Published upstream
Oct 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net: do not delay dst_entries_add() in dst_release() dst_entries_add() uses per-cpu data that might be freed at netns dismantle from ip6_route_net_exit() calling dst_entries_destroy() Before ip6_route_net_exit() can be called, we release all the dsts associated with this netns, via calls to dst_release(), which waits an rcu grace period before calling dst_destroy() dst_entries_add() use in dst_destroy() is racy, because dst_entries_destroy() could have been called already. Decrementing the number of dsts must happen sooner. Notes: 1) in CONFIG_XFRM case, dst_destroy() can call dst_release_immediate(child), this might also cause UAF if the child does not have DST_NOCOUNT set. IPSEC maintainers might take a look and see how to address this. 2) There is also discussion about removing this count of dst, which might happen in future kernels.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f88649721268999bdff09777847080a52004f691 <547087307bc19417b4f2bc85ba9664a3e8db5a6a || >=f88649721268999bdff09777847080a52004f691 <e3915f028b1f1c37e87542e5aadd33728c259d96 || >=f88649721268999bdff09777847080a52004f691 <a60db84f772fc3a906c6c4072f9207579c41166f || >=f88649721268999bdff09777847080a52004f691 <eae7435b48ffc8e9be0ff9cfeae40af479a609dd || >=f88649721268999bdff09777847080a52004f691 <3c7c918ec0aa3555372c5a57f18780b7a96c5cfc || >=f88649721268999bdff09777847080a52004f691 <ac888d58869bb99753e7652be19a151df9ecb35d || 86e48c03d774e01ccd71ecba4fc4b5c2bc0b5b41 || 591b1e1bb40152e22cee757f493046a0ca946bf8 || df90819dafcd6b97fc665f63a15752a570e227a2 || 9a4fe697023dbe6c25caa1f8b2153af869a29bd2 || >=3.10.50 <3.11 || >=3.12.26 <3.13 || >=3.14.14 <3.15 || >=3.15.7 <3.16 | 547087307bc19417b4f2bc85ba9664a3e8db5a6a, e3915f028b1f1c37e87542e5aadd33728c259d96, a60db84f772fc3a906c6c4072f9207579c41166f, eae7435b48ffc8e9be0ff9cfeae40af479a609dd, 3c7c918ec0aa3555372c5a57f18780b7a96c5cfc, ac888d58869bb99753e7652be19a151df9ecb35d, 3.11, 3.13, 3.15, 3.16 |
| Linux/Linuxgeneric | 3.16 | Not reported |
Published upstream
Oct 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net: do not delay dst_entries_add() in dst_release() dst_entries_add() uses per-cpu data that might be freed at netns dismantle from ip6_route_net_exit() calling dst_entries_destroy() Before ip6_route_net_exit() can be called, we release all the dsts associated with this netns, via calls to dst_release(), which waits an rcu grace period before calling dst_destroy() dst_entries_add() use in dst_destroy() is racy, because dst_entries_destroy() could have been called already. Decrementing the number of dsts must happen sooner. Notes: 1) in CONFIG_XFRM case, dst_destroy() can call dst_release_immediate(child), this might also cause UAF if the child does not have DST_NOCOUNT set. IPSEC maintainers might take a look and see how to address this. 2) There is also discussion about removing this count of dst, which might happen in future kernels.
Quoted source text, attributed separately from HOL analysis.