PT-2024-35656 · Linux+7 · Linux Kernel+7

Published

2024-11-22

·

Updated

2026-03-13

·

CVE-2024-53209

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.1.0-226bf9805506
Description The issue is related to the Linux kernel, specifically the bnxt en driver. When XDP is active, the MTU setting determines whether the aggregation ring will be used and the rx skb func handler. If the MTU is later changed, the aggregation ring setting may need to be changed, and it may become out-of-sync with the settings initially done in bnxt set rx skb mode(). This may result in random memory corruption and crashes as the HW may DMA data larger than the allocated buffer size.
Recommendations To address the issue, call bnxt set rx skb mode() within bnxt change mtu() to properly set the AGG rings configuration and update rx skb func based on the new MTU value. Additionally, BNXT FLAG NO AGG RINGS should be cleared at the beginning of bnxt set rx skb mode() to make sure it gets set or cleared based on the current MTU.
Note: The provided information does not specify the exact version that contains the fix for this issue. Therefore, it is recommended to update to the latest version of the Linux kernel to ensure you have the latest security patches.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2025-12647
AZL-57917
BDU:2025-12226
CVE-2024-53209
DLA-4271-1
DSA-5925-1
ECHO-F087-012B-FE16
OESA-2025-1093
OESA-2025-1097
OPENSUSE-SU-2025_0117-1
OPENSUSE-SU-2025_0153-1
OPENSUSE-SU-2025_0154-1
OPENSUSE-SU-2025_0556-1
OPENSUSE-SU-2025_0577-1
SUSE-SU-2025:0117-1
SUSE-SU-2025:0153-1
SUSE-SU-2025:0154-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:0556-1
SUSE-SU-2025:0577-1
SUSE-SU-2025:0577-2
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0577-1
SUSE-SU-2025_0577-2
USN-7276-1
USN-7277-1
USN-7310-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu