CVE-2024-50235: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear wdev->cqm_config pointer on free When we free wdev->cqm_config when unregistering, we also need to clear out the pointer since the same wdev/netdev may get re-registered in another network namespace, then destroyed later, running this code again, which results in a double-free.

Affected products

  • Linux Linux Kernel: from 6.1.57, before 6.1.116 (fixed in 6.1.116); from 6.5.7, before 6.6 (fixed in 6.6); from 6.6, before 6.6.60 (fixed in 6.6.60); from 6.7, before 6.11.7 (fixed in 6.11.7); version 6.12 only

Published 2024-11-09. Last modified 2026-06-17.