PT-2024-32206 · Linux+2 · Linux Kernel+2

Roger Quadros

·

Published

2024-08-20

·

Updated

2025-09-29

·

CVE-2024-46799

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference issue has been resolved in the Linux kernel. The issue occurs when the number of TX queues is set to 1, resulting in a NULL pointer dereference during XDP TX. This can be triggered using the ethtool command to set the number of TX queues to 1 and then using the xdp-trafficgen tool to transmit traffic on the affected interface. The issue is fixed by using actual TX queues instead of max TX queues when picking the TX channel in the am65 cpsw ndo xdp xmit() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-13260
BDU:2025-03584
CVE-2024-46799

Affected Products

Alt Linux
Astra Linux
Linux Kernel