PT-2024-30738 · Linux+9 · Linux Kernel+9

Published

2024-06-10

·

Updated

2025-09-29

·

CVE-2024-43880

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.50
Description The vulnerability is related to the mlxsw driver in the Linux kernel, which allows filters to share a single mask if their masks only differ in up to 8 consecutive bits. The driver uses the "objagg" library to perform mask aggregation, but the library does not support nested objects. The driver's object comparison function ignores the A-TCAM/C-TCAM indication, which can lead to nested objects and cause the library to return incorrect results. The issue can be reproduced in several minutes without the fix, but it does not reproduce in over an hour with the fix.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.50 or later. This version includes the fix for the mlxsw driver, which removes the object comparison function from both the driver and the library, ensuring that the lookup only returns exact matches.

Exploit

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:8856
ALSA-2024:8870
ALSA-2025_16880
BDU:2025-01930
CESA-2024_8856
CESA-2024_8870
CVE-2024-43880
DLA-3912-1
DLA-4008-1
INFSA-2024_8856
INFSA-2024_8870
MGASA-2024-0309
MGASA-2024-0310
OESA-2024-2292
OESA-2024-2293
OESA-2024-2295
OESA-2025-1097
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
RHSA-2024:8856
RHSA-2024:8870
RHSA-2024_8856
RHSA-2024_8870
RHSA-2025:10701
RLSA-2024:8856
RLSA-2024:8870
SUSE-SU-2024:3190-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:3483-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-7088-1
USN-7088-2
USN-7088-3
USN-7088-4
USN-7088-5
USN-7100-1
USN-7100-2
USN-7119-1
USN-7123-1
USN-7144-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7194-1
USN-7196-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu