cbcvebase.
CVE-2024-40928
published 2024-07-12

CVE-2024-40928: In the Linux kernel, the following vulnerability has been resolved: net: ethtool: fix the error condition in ethtool_get_phy_stats_ethtool() Clang static…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.7th percentile
In the Linux kernel, the following vulnerability has been resolved: net: ethtool: fix the error condition in ethtool_get_phy_stats_ethtool() Clang static checker (scan-build) warning: net/ethtool/ioctl.c:line 2233, column 2 Called function pointer is null (null dereference). Return '-EOPNOTSUPP' when 'ops->get_ethtool_phy_stats' is NULL to fix this typo error.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.9.7-1 (forky)linux 6.9.7-1 (forky)
linuxlinux
linuxlinux>= 201ed315f9676809cd5b20a39206e964106d4f27 < 6548d543a27449a1a3d8079925de93f5764d6f226548d543a27449a1a3d8079925de93f5764d6f22
linuxlinux>= 201ed315f9676809cd5b20a39206e964106d4f27 < 92196be82a4eb61813833dc62876fd198ae51ab192196be82a4eb61813833dc62876fd198ae51ab1
linuxlinux>= 201ed315f9676809cd5b20a39206e964106d4f27 < 0dcc53abf58d572d34c5313de85f607cd33fc6910dcc53abf58d572d34c5313de85f607cd33fc691
linuxlinux>= 72d1c4a07780e24827c29bad203a1167d67181ed < c3ba0557ab2ef15a3663e2fb9b1a3d628a8c3daac3ba0557ab2ef15a3663e2fb9b1a3d628a8c3daa
linuxlinux>= 981c6e178cf333ac9568665e6d786f795f5cb3ad < f9e57e7ca77393b5b7072800370370b02eaad0f8f9e57e7ca77393b5b7072800370370b02eaad0f8
linuxlinux>= c882f2178f22f3740e20a6bd6b8df1c0500301bf < 25504f7fe60058b2a9553a9e424fb7dd9683843e25504f7fe60058b2a9553a9e424fb7dd9683843e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 6.2 < 6.6.356.6.35
linuxlinux_kernel>= 6.7 < 6.9.66.9.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.