CVE-2024-46799

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-46799
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-46799.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-46799
Downstream
Published
2024-09-18T08:15:06Z
Modified
2025-08-09T19:01:28Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: ti: am65-cpsw: Fix NULL dereference on XDP_TX

If number of TX queues are set to 1 we get a NULL pointer dereference during XDP_TX.

~# ethtool -L eth0 tx 1 ~# ./xdp-trafficgen udp -A <ipv6-src> -a <ipv6-dst> eth0 -t 2 Transmitting on eth0 (ifindex 2) [ 241.135257] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000030

Fix this by using actual TX queues instead of max TX queues when picking the TX channel in am65cpswndoxdpxmit().

References

Affected packages