cbcvebase.
CVE-2024-27046
published 2024-05-01

CVE-2024-27046: In the Linux kernel, the following vulnerability has been resolved: nfp: flower: handle acti_netdevs allocation failure The kmalloc_array() in…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.30%
21.9th percentile
In the Linux kernel, the following vulnerability has been resolved: nfp: flower: handle acti_netdevs allocation failure The kmalloc_array() in nfp_fl_lag_do_work() will return null, if the physical memory has run out. As a result, if we dereference the acti_netdevs, the null pointer dereference bugs will happen. This patch adds a check to judge whether allocation failure occurs. If it happens, the delayed work will be rescheduled and try again.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= bb9a8d031140f186d13d82f57b0f5646d596652f < d746889db75a76aeee95fb705b8e1ac28c684a2ed746889db75a76aeee95fb705b8e1ac28c684a2e
linuxlinux>= bb9a8d031140f186d13d82f57b0f5646d596652f < 3b1e8a617eb0f4cdc19def530047a95b5abde07d3b1e8a617eb0f4cdc19def530047a95b5abde07d
linuxlinux>= bb9a8d031140f186d13d82f57b0f5646d596652f < 928705e341010dd910fdece61ccb974f494a758f928705e341010dd910fdece61ccb974f494a758f
linuxlinux>= bb9a8d031140f186d13d82f57b0f5646d596652f < 0d387dc503f9a53e6d1f6e9dd0292d38f083eba50d387dc503f9a53e6d1f6e9dd0292d38f083eba5
linuxlinux>= bb9a8d031140f186d13d82f57b0f5646d596652f < c9b4e220dd18f79507803f38a55d53b483f6c9c3c9b4e220dd18f79507803f38a55d53b483f6c9c3
linuxlinux>= bb9a8d031140f186d13d82f57b0f5646d596652f < 408ba7fd04f959c61b50db79c983484312fea642408ba7fd04f959c61b50db79c983484312fea642
linuxlinux>= bb9a8d031140f186d13d82f57b0f5646d596652f < c8df9203bf22c66fa26e8d8c7f8ce181cf88099dc8df9203bf22c66fa26e8d8c7f8ce181cf88099d
linuxlinux>= bb9a8d031140f186d13d82f57b0f5646d596652f < 9d8eb1238377cd994829f9162ae396a84ae037b29d8eb1238377cd994829f9162ae396a84ae037b2
linuxlinux>= bb9a8d031140f186d13d82f57b0f5646d596652f < 84e95149bd341705f0eca6a7fcb955c54880500284e95149bd341705f0eca6a7fcb955c548805002
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 4.18 < 4.19.3114.19.311
linuxlinux_kernel>= 4.20 < 5.4.2735.4.273
linuxlinux_kernel>= 5.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 5.5 < 5.10.2145.10.214
linuxlinux_kernel>= 6.2 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.