Executive Summary

Informations
Name CVE-2024-46799 First vendor Publication 2024-09-18
Vendor Cve Last vendor Modification 2024-09-23

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.6 Temporal Score 5.5
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: ti: am65-cpsw: Fix NULL dereference on XDP_TX

If number of TX queues are set to 1 we get a NULL pointer dereference during XDP_TX.

~# ethtool -L eth0 tx 1 ~# ./xdp-trafficgen udp -A -a eth0 -t 2 Transmitting on eth0 (ifindex 2) [ 241.135257] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000030

Fix this by using actual TX queues instead of max TX queues when picking the TX channel in am65_cpsw_ndo_xdp_xmit().

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-46799

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-476 NULL Pointer Dereference

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3632

Sources (Detail)

https://git.kernel.org/stable/c/0a50c35277f96481a5a6ed5faf347f282040c57d
https://git.kernel.org/stable/c/2e7189d2b1de51fc2567676cd4f96c0fe0960b9f
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
Date Informations
2024-11-23 03:03:30
  • Multiple Updates
2024-11-22 03:01:39
  • Multiple Updates
2024-11-20 02:59:59
  • Multiple Updates
2024-11-14 03:00:17
  • Multiple Updates
2024-11-09 03:00:17
  • Multiple Updates
2024-10-26 02:57:40
  • Multiple Updates
2024-10-25 02:59:32
  • Multiple Updates
2024-10-23 02:58:44
  • Multiple Updates
2024-10-03 02:53:53
  • Multiple Updates
2024-10-02 00:27:47
  • Multiple Updates
2024-09-23 21:27:25
  • Multiple Updates
2024-09-20 17:27:27
  • Multiple Updates
2024-09-18 13:27:29
  • First insertion