PT-2024-3401 · Linux · Linux Kernel

Jiri Pirko

·

Published

2024-02-08

·

Updated

2024-04-04

·

CVE-2024-26724

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.8.0-rc2jiri+
Description: The vulnerability is related to a use-after-free issue in the mlx5 dpll remove function, which can cause a denial-of-service. The issue occurs when a delayed work timer is triggered, allowing an attacker to exploit the vulnerability. The estimated number of potentially affected devices is not specified.
Recommendations: To resolve the issue, update the Linux kernel to version 6.8.0-rc2jiri or later. As a temporary workaround, consider disabling the mlx5 dpll remove function until a patch is available. Restrict access to the vulnerable module mlx5 dpll to minimize the risk of exploitation. Avoid using the mlx5 dpll probe function in the affected API endpoint until the issue is resolved.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03673
CVE-2024-26724

Affected Products

Linux Kernel