PT-2024-32230 · Linux+7 · Linux Kernel+7

Syzbot

·

Published

2024-09-05

·

Updated

2025-09-29

·

CVE-2024-46828

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the bulk flow accounting logic in the sch cake component of the Linux kernel. When the host fairness mode is disabled, a hash collision can cause a spurious decrement of the bulk flow counters, leading to a wrap-around and potentially causing an array overflow when the host fairness mode is re-enabled. This can happen when a hash collision occurs, and the state of the hash bucket is updated to match the new packet that collided. The patch fixes the issue by introducing a conditional check on decrement, similar to the one used on increment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-12535
BDU:2025-01656
CVE-2024-46828
DLA-3912-1
DLA-4008-1
DSA-5782-1
INFSA-2025_6966
OESA-2024-2255
OESA-2024-2257
OESA-2024-2258
OESA-2025-1078
OPENSUSE-SU-2024_3983-1
OPENSUSE-SU-2024_3984-1
OPENSUSE-SU-2024_3985-1
OPENSUSE-SU-2024_3986-1
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4316-1
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2024:3983-1
SUSE-SU-2024:3984-1
SUSE-SU-2024:3985-1
SUSE-SU-2024:3986-1
SUSE-SU-2024:4314-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7088-1
USN-7088-2
USN-7088-3
USN-7088-4
USN-7088-5
USN-7100-1
USN-7100-2
USN-7119-1
USN-7123-1
USN-7144-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7194-1
USN-7196-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu