PT-2024-6981 · Linux+6 · Linux Kernel+6

Published

2024-06-28

·

Updated

2025-09-29

·

CVE-2024-42148

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a read/write out of bounds that occurs on the array "struct stats query entry query" present inside the "bnx2x fw stats req" struct in "drivers/net/ethernet/broadcom/bnx2x/bnx2x.h". This happens when using a system with 32 physical cpu cores or more, or when the user defines a number of Ethernet queues greater than or equal to FP SB MAX E1x using the num queues module parameter. The array has a total size of 19, and accesses to it are offset-ted by BNX2X FIRST QUEUE QUERY IDX. The total number of Ethernet queues should not exceed FP SB MAX E1x (16), but one of these queues is reserved for FCOE. The number of Ethernet queues should be set to [FP SB MAX E1x -1] (15) if FCOE is enabled or [FP SB MAX E1x] (16) if it is not.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-10465
ALT-PU-2024-12537
ALT-PU-2024-13979
ALT-PU-2024-14046
BDU:2024-08230
CVE-2024-42148
DLA-4008-1
DSA-5747-1
MGASA-2024-0277
MGASA-2024-0278
OESA-2024-1992
OESA-2024-1994
OESA-2024-1995
OESA-2024-1996
OESA-2025-1078
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
SUSE-SU-2024:3189-1
SUSE-SU-2024:3190-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3251-1
SUSE-SU-2024:3252-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:3483-1
SUSE-SU-2024:3617-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-6999-1
USN-6999-2
USN-7003-1
USN-7003-2
USN-7003-3
USN-7003-4
USN-7003-5
USN-7004-1
USN-7005-1
USN-7005-2
USN-7006-1
USN-7007-1
USN-7007-2
USN-7007-3
USN-7008-1
USN-7009-1
USN-7009-2
USN-7019-1
USN-7029-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu