PT-2024-26773 · Linux+4 · Linux Kernel+4
Balazs Nemeth
·
Published
2024-03-20
·
Updated
2025-05-20
·
CVE-2024-35889
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue arises when a packet type is unknown to the driver, causing
idpf rx process skb fields to return early without calling eth type trans to set the skb protocol or the network layer handler. This is particularly problematic if tcpdump is running when such a packet is received, as it would cause a kernel panic. To resolve this, eth type trans should be called for every single packet, even when the packet type is unknown.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu