Bug 2313147 (CVE-2024-46799) - CVE-2024-46799 kernel: net: ethernet: ti: am65-cpsw: Fix NULL dereference on XDP_TX
Summary: CVE-2024-46799 kernel: net: ethernet: ti: am65-cpsw: Fix NULL dereference on ...
Keywords:
Status: NEW
Alias: CVE-2024-46799
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2313282
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-09-18 08:23 UTC by OSIDB Bzimport
Modified: 2024-10-02 14:45 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2024-09-18 08:23:37 UTC
In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: ti: am65-cpsw: Fix NULL dereference on XDP_TX

If number of TX queues are set to 1 we get a NULL pointer
dereference during XDP_TX.

~# ethtool -L eth0 tx 1
~# ./xdp-trafficgen udp -A <ipv6-src> -a <ipv6-dst> eth0 -t 2
Transmitting on eth0 (ifindex 2)
[  241.135257] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000030

Fix this by using actual TX queues instead of max TX queues
when picking the TX channel in am65_cpsw_ndo_xdp_xmit().


Note You need to log in before you can comment on or make changes to this bug.