CVE-2024-42224Improper Check for Unusual or Exceptional Conditions in Linux

Severity
6.1MEDIUMNVD
OSV7.8OSV5.5OSV5.3
EPSS
0.0%
top 89.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 30
Latest updateAug 14

Description

In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Correct check for empty list Since commit a3c53be55c95 ("net: dsa: mv88e6xxx: Support multiple MDIO busses") mv88e6xxx_default_mdio_bus() has checked that the return value of list_first_entry() is non-NULL. This appears to be intended to guard against the list chip->mdios being empty. However, it is not the correct check as the implementation of list_first_entry is not designed to return NULL for empty li

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:HExploitability: 1.8 | Impact: 4.2

Affected Packages14 packages

Patches

🔴Vulnerability Details

22
OSV
linux-gkeop vulnerabilities2024-12-12
OSV
linux-azure vulnerabilities2024-10-17
OSV
linux-aws-6.8, linux-oracle-6.8 vulnerabilities2024-10-11
OSV
linux-raspi-5.4 vulnerabilities2024-10-01
OSV
linux-raspi vulnerabilities2024-09-26

📋Vendor Advisories

23
CISA ICS
Siemens Third-Party Components in SINEC OS2025-08-14
Ubuntu
Linux kernel (GKE) vulnerabilities2024-12-12
Ubuntu
Linux kernel (Azure) vulnerabilities2024-10-17
Ubuntu
Linux kernel vulnerabilities2024-10-11
Ubuntu
Linux kernel vulnerabilities2024-10-01