cbcvebase.
CVE-2024-50097
published 2024-11-05

CVE-2024-50097: In the Linux kernel, the following vulnerability has been resolved: net: fec: don't save PTP state if PTP is unsupported Some platforms (such as i.MX25 and…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.7th percentile
In the Linux kernel, the following vulnerability has been resolved: net: fec: don't save PTP state if PTP is unsupported Some platforms (such as i.MX25 and i.MX27) do not support PTP, so on these platforms fec_ptp_init() is not called and the related members in fep are not initialized. However, fec_ptp_save_state() is called unconditionally, which causes the kernel to panic. Therefore, add a condition so that fec_ptp_save_state() is not called if PTP is not supported.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.11.4-1 (forky)linux 6.11.4-1 (forky)
linuxlinux
linuxlinux>= 5763541f24d8ab2053d80fddb8479a2d0df8fd4f < 3192e8d4a1ef9fc9bd7a59cdce51543367e5edd63192e8d4a1ef9fc9bd7a59cdce51543367e5edd6
linuxlinux>= 6.10.14 < 6.116.11
linuxlinux>= 6.11.3 < 6.11.46.11.4
linuxlinux>= 6.6.55 < 6.6.576.6.57
linuxlinux>= a1477dc87dc4996dcf65a4893d4e2c3a6b593002 < 6be063071a457767ee229db13f019c2ec03bfe446be063071a457767ee229db13f019c2ec03bfe44
linuxlinux>= dc5fb264168c3aa8842b2db547c2b5c7df346454 < 7745e14f4c036ce94a5eb05d06e49b0d84b306f97745e14f4c036ce94a5eb05d06e49b0d84b306f9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 6.10.4 < 6.116.11
linuxlinux_kernel>= 6.6.55 < 6.6.576.6.57
linuxlinux_kernel>= 6.7 < 6.11.46.11.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.