cbcvebase.
CVE-2024-53043
published 2024-11-19

CVE-2024-53043: In the Linux kernel, the following vulnerability has been resolved: mctp i2c: handle NULL header address daddr can be NULL if there is no neighbour table entry…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: mctp i2c: handle NULL header address daddr can be NULL if there is no neighbour table entry present, in that case the tx packet should be dropped. saddr will usually be set by MCTP core, but check for NULL in case a packet is transmitted by a different protocol.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= f5b8abf9fc3dacd7529d363e26fe8230935d65f8 < 4707893315802a0917231b94cb20cbe50ccbfe034707893315802a0917231b94cb20cbe50ccbfe03
linuxlinux>= f5b8abf9fc3dacd7529d363e26fe8230935d65f8 < 8e886e44397ba89f6e8da8471386112b4f5b67b78e886e44397ba89f6e8da8471386112b4f5b67b7
linuxlinux>= f5b8abf9fc3dacd7529d363e26fe8230935d65f8 < 8c222adadc1612e4f097688875962a28e3f5ab448c222adadc1612e4f097688875962a28e3f5ab44
linuxlinux>= f5b8abf9fc3dacd7529d363e26fe8230935d65f8 < 01e215975fd80af81b5b79f009d49ddd35976c1301e215975fd80af81b5b79f009d49ddd35976c13
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.7-16.11.7-1
linuxlinux_kernel>= 0 < 6.11.7-16.11.7-1
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.18 < 6.1.1166.1.116
linuxlinux_kernel>= 6.2 < 6.6.606.6.60
linuxlinux_kernel>= 6.7 < 6.11.76.11.7
msrcazl3_kernel_6.6.57.1-7_on_azure_linux_3.0
msrcazl3_kernel_6.6.64.2-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.