CVE-2024-50298

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
19/11/2024
Last modified:
01/10/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: enetc: allocate vf_state during PF probes<br /> <br /> In the previous implementation, vf_state is allocated memory only when VF<br /> is enabled. However, net_device_ops::ndo_set_vf_mac() may be called before<br /> VF is enabled to configure the MAC address of VF. If this is the case,<br /> enetc_pf_set_vf_mac() will access vf_state, resulting in access to a null<br /> pointer. The simplified error log is as follows.<br /> <br /> root@ls1028ardb:~# ip link set eno0 vf 1 mac 00:0c:e7:66:77:89<br /> [ 173.543315] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004<br /> [ 173.637254] pc : enetc_pf_set_vf_mac+0x3c/0x80 Message from sy<br /> [ 173.641973] lr : do_setlink+0x4a8/0xec8<br /> [ 173.732292] Call trace:<br /> [ 173.734740] enetc_pf_set_vf_mac+0x3c/0x80<br /> [ 173.738847] __rtnl_newlink+0x530/0x89c<br /> [ 173.742692] rtnl_newlink+0x50/0x7c<br /> [ 173.746189] rtnetlink_rcv_msg+0x128/0x390<br /> [ 173.750298] netlink_rcv_skb+0x60/0x130<br /> [ 173.754145] rtnetlink_rcv+0x18/0x24<br /> [ 173.757731] netlink_unicast+0x318/0x380<br /> [ 173.761665] netlink_sendmsg+0x17c/0x3c8

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.1 (including) 6.6.61 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.11.8 (excluding)
cpe:2.3:o:linux:linux_kernel:6.12:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc6:*:*:*:*:*:*