CVE-2024-49945
CSIRTS triage
- What
- The ncsi work structure is freed without being properly disabled first, causing potential use-after-free or memory corruption.
- Who is affected
- Linux systems with NCSI (NC-SI) network controller support enabled.
- Urgency
- Medium severity; memory corruption vulnerability could lead to crashes or potential code execution depending on exploitation.
- Action
- Apply the kernel patch that disables ncsi work before freeing the structure or upgrade to a patched kernel.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2024-49945
Get an email if CVE-2024-49945 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
Advisory coverage (1)
- mediumCVE-2024-49945: net/ncsi: Disable the ncsi work before freeing the associated structuremsrc · 2026-08-06
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2024-49945)