CVE-2024-56660
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
27/12/2024
Last modified:
06/01/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net/mlx5: DR, prevent potential error pointer dereference<br />
<br />
The dr_domain_add_vport_cap() function generally returns NULL on error<br />
but sometimes we want it to return ERR_PTR(-EBUSY) so the caller can<br />
retry. The problem here is that "ret" can be either -EBUSY or -ENOMEM<br />
and if it&#39;s and -ENOMEM then the error pointer is propogated back and<br />
eventually dereferenced in dr_ste_v0_build_src_gvmi_qpn_tag().
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.121 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.67 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.6 (excluding) |
cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:6.13:rc2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page