cbcvebase.
CVE-2024-56660
published 2024-12-27

CVE-2024-56660: In the Linux kernel, the following vulnerability has been resolved: net/mlx5: DR, prevent potential error pointer dereference The dr_domain_add_vport_cap()…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.5th percentile
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: DR, prevent potential error pointer dereference The dr_domain_add_vport_cap() function generally returns NULL on error but sometimes we want it to return ERR_PTR(-EBUSY) so the caller can retry. The problem here is that "ret" can be either -EBUSY or -ENOMEM and if it's and -ENOMEM then the error pointer is propogated back and eventually dereferenced in dr_ste_v0_build_src_gvmi_qpn_tag().

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 11a45def2e197532c46aa908dedd52bc1ee378a2 < 61f720e801443d4e2a3c0261eda4ad8431458dca61f720e801443d4e2a3c0261eda4ad8431458dca
linuxlinux>= 11a45def2e197532c46aa908dedd52bc1ee378a2 < 325cf73a1b449fea3158ab99d03a7a717aad1618325cf73a1b449fea3158ab99d03a7a717aad1618
linuxlinux>= 11a45def2e197532c46aa908dedd52bc1ee378a2 < a59c61a1869ceefc65ef02886f91e8cd0062211fa59c61a1869ceefc65ef02886f91e8cd0062211f
linuxlinux>= 11a45def2e197532c46aa908dedd52bc1ee378a2 < 11776cff0b563c8b8a4fa76cab620bfb633a8cb811776cff0b563c8b8a4fa76cab620bfb633a8cb8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 5.16 < 6.1.1216.1.121
linuxlinux_kernel>= 6.2 < 6.6.676.6.67
linuxlinux_kernel>= 6.7 < 6.12.66.12.6
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.76.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.