Answer in brief
CVE-2024-50130 records a Unknown severity vulnerability in netfilter: bpf: must hold reference on net namespace. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=84601d6ee68ae820dec97450934797046d62db4b <f41bd93b3e0508edc7ba820357f949071dcc0acc || >=84601d6ee68ae820dec97450934797046d62db4b <d0d7939543a1b3bb93af9a18d258a774daf8f162 || >=84601d6ee68ae820dec97450934797046d62db4b <1230fe7ad3974f7bf6c78901473e039b34d4fb1f | f41bd93b3e0508edc7ba820357f949071dcc0acc, d0d7939543a1b3bb93af9a18d258a774daf8f162, 1230fe7ad3974f7bf6c78901473e039b34d4fb1f |
| Linux/Linuxgeneric | 6.4 | Not reported |
Published upstream
Nov 5, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: must hold reference on net namespace BUG: KASAN: slab-use-after-free in __nf_unregister_net_hook+0x640/0x6b0 Read of size 8 at addr ffff8880106fe400 by task repro/72= bpf_nf_link_release+0xda/0x1e0 bpf_link_free+0x139/0x2d0 bpf_link_release+0x68/0x80 __fput+0x414/0xb60 Eric says: It seems that bpf was able to defer the __nf_unregister_net_hook() after exit()/close() time. Perhaps a netns reference is missing, because the netns has been dismantled/freed already. bpf_nf_link_attach() does : link->net = net; But I do not see a reference being taken on net. Add such a reference and release it after hook unreg. Note that I was unable to get syzbot reproducer to work, so I do not know if this resolves this splat.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-50130 records a Unknown severity vulnerability in netfilter: bpf: must hold reference on net namespace. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=84601d6ee68ae820dec97450934797046d62db4b <f41bd93b3e0508edc7ba820357f949071dcc0acc || >=84601d6ee68ae820dec97450934797046d62db4b <d0d7939543a1b3bb93af9a18d258a774daf8f162 || >=84601d6ee68ae820dec97450934797046d62db4b <1230fe7ad3974f7bf6c78901473e039b34d4fb1f | f41bd93b3e0508edc7ba820357f949071dcc0acc, d0d7939543a1b3bb93af9a18d258a774daf8f162, 1230fe7ad3974f7bf6c78901473e039b34d4fb1f |
| Linux/Linuxgeneric | 6.4 | Not reported |
Published upstream
Nov 5, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: must hold reference on net namespace BUG: KASAN: slab-use-after-free in __nf_unregister_net_hook+0x640/0x6b0 Read of size 8 at addr ffff8880106fe400 by task repro/72= bpf_nf_link_release+0xda/0x1e0 bpf_link_free+0x139/0x2d0 bpf_link_release+0x68/0x80 __fput+0x414/0xb60 Eric says: It seems that bpf was able to defer the __nf_unregister_net_hook() after exit()/close() time. Perhaps a netns reference is missing, because the netns has been dismantled/freed already. bpf_nf_link_attach() does : link->net = net; But I do not see a reference being taken on net. Add such a reference and release it after hook unreg. Note that I was unable to get syzbot reproducer to work, so I do not know if this resolves this splat.
Quoted source text, attributed separately from HOL analysis.