PT-2024-33979 · Linux+6 · Linux Kernel+6
Shay Drory
·
Published
2024-11-07
·
Updated
2025-10-03
·
CVE-2024-50147
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.61
Description:
A null pointer dereference issue has been identified in the Linux kernel's net/mlx5 component. The problem occurs due to incorrect initialization of the command bitmask, specifically the bit for the
MANAGE PAGES command. This can lead to a null pointer dereference error when mlx5 cmd trigger completions() attempts to trigger completion for the MANAGE PAGES command before it has been invoked. The issue can result in a null-ptr-deref error, as seen in the mlx5 cmd trigger completions+0x1db/0x600 function.Recommendations:
To resolve this issue, update to Linux kernel version 6.6.61 or later. As a temporary workaround, consider disabling the
mlx5 cmd trigger completions() function until a patch is available. Restrict access to the net/mlx5 component to minimize the risk of exploitation. Avoid using the MANAGE PAGES command in the affected API endpoint until the issue is resolved.Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu