PT-2024-32172 · Linux+5 · Linux Kernel+5

Martin Kafai Lau

+1

·

Published

2024-07-10

·

Updated

2026-04-20

·

CVE-2024-46754

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the Linux kernel, where the lwt seg6 related BPF ops can be invoked via bpf test run() without entering input action end bpf() first. This is because the per-CPU variable seg6 bpf srh states::srh is never assigned in the self test case, but each BPF function expects it. The problem probably didn't work since it was introduced in commit 04d4b274e2a ("ipv6: sr: Add seg6local action End.BPF").
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
AZL-62615
AZL-68297
BDU:2026-04535
CVE-2024-46754
ECHO-768D-5A29-631E
INFSA-2025_6966
OESA-2024-2255
OESA-2024-2257
OESA-2024-2258
OESA-2024-2296
OPENSUSE-SU-2024_3983-1
OPENSUSE-SU-2024_3984-1
OPENSUSE-SU-2024_3985-1
OPENSUSE-SU-2024_3986-1
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2024:3983-1
SUSE-SU-2024:3984-1
SUSE-SU-2024:3985-1
SUSE-SU-2024:3986-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7196-1

Affected Products

Debian
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu