CVE-2024-46833
published 2024-09-27CVE-2024-46833: In the Linux kernel, the following vulnerability has been resolved: net: hns3: void array out of bound when loop tnl_num When query reg inf of SSU, it loops…
PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: hns3: void array out of bound when loop tnl_num
When query reg inf of SSU, it loops tnl_num times. However, tnl_num comes
from hardware and the length of array is a fixed value. To void array out
of bound, make sure the loop time is not greater than the length of array
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.10.11-1 (forky) | linux 6.10.11-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 8a4bda8cb9e43e1fae96c4c4aa94069f49dc3a68 < c33a9806dc806bcb4a31dc71fb06979219181ad4 | c33a9806dc806bcb4a31dc71fb06979219181ad4 |
| linux | linux | >= 8a4bda8cb9e43e1fae96c4c4aa94069f49dc3a68 < 86db7bfb06704ef17340eeae71c832f21cfce35c | 86db7bfb06704ef17340eeae71c832f21cfce35c |
| linux | linux_kernel | < 6.10.10 | 6.10.10 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.10.11-1 | 6.10.11-1 |
| linux | linux_kernel | >= 0 < 6.10.11-1 | 6.10.11-1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: hns3: void array out of bound when loop tnl_num
vendor_redhat·2024-09-27·CVSS 7.8
CVE-2024-46833 [HIGH] CWE-125 kernel: net: hns3: void array out of bound when loop tnl_num
kernel: net: hns3: void array out of bound when loop tnl_num
In the Linux kernel, the following vulnerability has been resolved:
net: hns3: void array out of bound when loop tnl_num
When query reg inf of SSU, it loops tnl_num times. However, tnl_num comes
from hardware and the length of array is a fixed value. To void array out
of bound, make sure the loop time is not greater than the length of array
An out-of-bounds memory access flaw was found in the Linux kernel’s Hisilicon Network driver in how the hardware returns an incorrect value to the driver. This flaw allows a local user to crash or potentially escalate their privileges on the system if using malicious hardware.
Statement: The kernel configuration parameter CONFIG_HNS3 is disabled, so this is listed as not affected for all ve
Debian
CVE-2024-46833: linux - In the Linux kernel, the following vulnerability has been resolved: net: hns3: ...
vendor_debian·2024·CVSS 7.8
CVE-2024-46833 [HIGH] CVE-2024-46833: linux - In the Linux kernel, the following vulnerability has been resolved: net: hns3: ...
In the Linux kernel, the following vulnerability has been resolved: net: hns3: void array out of bound when loop tnl_num When query reg inf of SSU, it loops tnl_num times. However, tnl_num comes from hardware and the length of array is a fixed value. To void array out of bound, make sure the loop time is not greater than the length of array
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.10.11-1)
sid: resolved (fixed in 6.10.11-1)
trixie: resolved (fixed in 6.10.11-1)
GHSA
GHSA-q973-qv3f-rvgr: In the Linux kernel, the following vulnerability has been resolved:
net: hns3: void array out of bound when loop tnl_num
When query reg inf of SSU,
ghsa_unreviewed·2024-09-27
CVE-2024-46833 [HIGH] CWE-129 GHSA-q973-qv3f-rvgr: In the Linux kernel, the following vulnerability has been resolved:
net: hns3: void array out of bound when loop tnl_num
When query reg inf of SSU,
In the Linux kernel, the following vulnerability has been resolved:
net: hns3: void array out of bound when loop tnl_num
When query reg inf of SSU, it loops tnl_num times. However, tnl_num comes
from hardware and the length of array is a fixed value. To void array out
of bound, make sure the loop time is not greater than the length of array
OSV
CVE-2024-46833: In the Linux kernel, the following vulnerability has been resolved: net: hns3: void array out of bound when loop tnl_num When query reg inf of SSU, it
osv·2024-09-27·CVSS 7.8
CVE-2024-46833 [HIGH] CVE-2024-46833: In the Linux kernel, the following vulnerability has been resolved: net: hns3: void array out of bound when loop tnl_num When query reg inf of SSU, it
In the Linux kernel, the following vulnerability has been resolved: net: hns3: void array out of bound when loop tnl_num When query reg inf of SSU, it loops tnl_num times. However, tnl_num comes from hardware and the length of array is a fixed value. To void array out of bound, make sure the loop time is not greater than the length of array
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-27
Published