cbcvebase.
CVE-2024-42224
published 2024-07-30

CVE-2024-42224: In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Correct check for empty list Since commit a3c53be55c95 ("net: dsa…

PriorityP423medium6.1CVSS 3.1
AVLACLPRLUINSUCNILAH
EPSS
0.23%
14.2th percentile
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Correct check for empty list Since commit a3c53be55c95 ("net: dsa: mv88e6xxx: Support multiple MDIO busses") mv88e6xxx_default_mdio_bus() has checked that the return value of list_first_entry() is non-NULL. This appears to be intended to guard against the list chip->mdios being empty. However, it is not the correct check as the implementation of list_first_entry is not designed to return NULL for empty lists. Instead, use list_first_entry_or_null() which does return NULL if the list is empty. Flagged by Smatch. Compile tested only.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= a3c53be55c955b7150cda17874c3fcb4eeb97a89 < 47d28dde172696031c880c5778633cdca30394ee47d28dde172696031c880c5778633cdca30394ee
linuxlinux>= a3c53be55c955b7150cda17874c3fcb4eeb97a89 < 3bf8d70e1455f87856640c3433b3660a310016183bf8d70e1455f87856640c3433b3660a31001618
linuxlinux>= a3c53be55c955b7150cda17874c3fcb4eeb97a89 < 2a2fe25a103cef73cde356e6d09da10f607e93f52a2fe25a103cef73cde356e6d09da10f607e93f5
linuxlinux>= a3c53be55c955b7150cda17874c3fcb4eeb97a89 < 8c2c3cca816d074c75a2801d1ca0dea7b01481148c2c3cca816d074c75a2801d1ca0dea7b0148114
linuxlinux>= a3c53be55c955b7150cda17874c3fcb4eeb97a89 < aa03f591ef31ba603a4a99d05d25a0f21ab1cd89aa03f591ef31ba603a4a99d05d25a0f21ab1cd89
linuxlinux>= a3c53be55c955b7150cda17874c3fcb4eeb97a89 < 3f25b5f1635449036692a44b771f39f772190c1d3f25b5f1635449036692a44b771f39f772190c1d
linuxlinux>= a3c53be55c955b7150cda17874c3fcb4eeb97a89 < f75625db838ade28f032dacd0f0c8baca42ecde4f75625db838ade28f032dacd0f0c8baca42ecde4
linuxlinux>= a3c53be55c955b7150cda17874c3fcb4eeb97a89 < 4c7f3950a9fd53a62b156c0fe7c3a2c43b0ba19b4c7f3950a9fd53a62b156c0fe7c3a2c43b0ba19b
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-45.456.8.0-45.45
linuxlinux_kernel>= 0 < 4.15.0-229.2414.15.0-229.241
linuxlinux_kernel>= 4.11 < 4.19.3184.19.318
linuxlinux_kernel>= 4.20 < 5.4.2805.4.280
linuxlinux_kernel>= 5.11 < 5.15.1635.15.163
linuxlinux_kernel>= 5.16 < 6.1.986.1.98
linuxlinux_kernel>= 5.5 < 5.10.2225.10.222
linuxlinux_kernel>= 6.2 < 6.6.396.6.39

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.