Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-44970— net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink

CVSS 9.8 · Critical EPSS 0.56% · P44

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 10

VendorProductVersion RangeStatus
LinuxLinuxf97d5c2a453e26071e3b0ec12161de57c4a237c4< 7b379353e9144e1f7460ff15f39862012c9d0d78affected
f97d5c2a453e26071e3b0ec12161de57c4a237c4< 650e24748e1e0a7ff91d5c72b72a2f2a452b5b76affected
f97d5c2a453e26071e3b0ec12161de57c4a237c4< 50d8009a0ac02c3311b23a0066511f8337bd88d9affected
f97d5c2a453e26071e3b0ec12161de57c4a237c4< fba8334721e266f92079632598e46e5f89082f30affected
5.16affected
< 5.16unaffected
6.1.105≤ 6.1.*unaffected
6.6.46≤ 6.6.*unaffected
… +2 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-44970

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink When all the strides in a WQE have been consumed, the WQE is unlinked from the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possible to receive CQEs with 0 consumed strides for the same WQE even after the WQE is fully consumed and unlinked. This triggers an additional unlink for the same wqe which corrupts the linked list. Fix this scenario by accepting 0 sized consumed strides without unlinking the WQE again.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于net/mlx5e组件存在逻辑漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux f97d5c2a453e26071e3b0ec12161de57c4a237c4 ~ 7b379353e9144e1f7460ff15f39862012c9d0d78 -
LinuxLinux 5.16 -

II. Public POCs for CVE-2024-44970

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-44970

登录查看更多情报信息。

Patches & Fixes for CVE-2024-44970 (4)

Same Patch Batch · Linux · 2024-09-04 · 58 CVEs total

CVE-2024-4498410.0 CRITICALbnxt_en: Fix double DMA unmapping for XDP_REDIRECT
CVE-2024-449859.8 CRITICALipv6: prevent possible UAF in ip6_xmit()
CVE-2024-449989.8 CRITICALatm: idt77252: prevent use after free in dequeue_rx()
CVE-2024-449888.8 HIGHnet: dsa: mv88e6xxx: Fix out-of-bound access
CVE-2024-449948.8 HIGHiommu: Restore lost return in iommu_report_device_fault()
CVE-2024-449868.1 HIGHipv6: fix possible UAF in ip6_finish_output2()
CVE-2024-449738.1 HIGHmm, slub: do not call do_slab_free for kfence object
CVE-2024-449877.8 HIGHipv6: prevent UAF in ip6_send_skb()
CVE-2024-449517.8 HIGHserial: sc16is7xx: fix TX fifo corruption
CVE-2024-449497.8 HIGHparisc: fix a possible DMA corruption
CVE-2024-449597.8 HIGHtracefs: Use generic inode RCU for synchronizing freeing
CVE-2024-449547.8 HIGHALSA: line6: Fix racy access to midibuf
CVE-2024-450007.8 HIGHfs/netfs/fscache_cookie: add missing "n_accesses" check
CVE-2024-449667.8 HIGHbinfmt_flat: Fix corruption when not offsetting data start
CVE-2024-449977.8 HIGHnet: ethernet: mtk_wed: fix use-after-free panic in mtk_wed_setup_tc_block_cb()
CVE-2024-449747.8 HIGHmptcp: pm: avoid possible UaF when selecting endp
CVE-2024-449957.8 HIGHnet: hns3: fix a deadlock problem when config TC during resetting
CVE-2024-449787.8 HIGHdrm/xe: Free job before xe_exec_queue_put
CVE-2024-449677.8 HIGHdrm/mgag200: Bind I2C lifetime to DRM device
CVE-2024-449927.5 HIGHsmb/client: avoid possible NULL dereference in cifs_free_subrequest()

Showing top 20 of 58 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-44970

No comments yet


Leave a comment