{"id":"DEBIAN-CVE-2024-50260","details":"In the Linux kernel, the following vulnerability has been resolved:  sock_map: fix a NULL pointer dereference in sock_map_link_update_prog()  The following race condition could trigger a NULL pointer dereference:  sock_map_link_detach():\t\tsock_map_link_update_prog():    mutex_lock(&sockmap_mutex);    ...    sockmap_link-\u003emap = NULL;    mutex_unlock(&sockmap_mutex);    \t\t\t\t   mutex_lock(&sockmap_mutex); \t\t\t\t   ... \t\t\t\t   sock_map_prog_link_lookup(sockmap_link-\u003emap); \t\t\t\t   mutex_unlock(&sockmap_mutex);    \u003ccontinue\u003e  Fix it by adding a NULL pointer check. In this specific case, it makes no sense to update a link which is being released.","modified":"2026-09-15T09:03:15.565417528Z","published":"2024-11-09T11:15:11.550Z","upstream":["CVE-2024-50260"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-50260"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50260.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50260.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}