CVE-2024-46857
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Sep 27, 2024
Updated: Oct 1, 2024
CWE ID 476
Summary
CVE-2024-46857: A vulnerability in the Linux kernel's MLX5 driver has been addressed. When attempting to set the bridge mode attribute with no Virtual Functions (VFs), the system encounters a NULL pointer dereference. This bug occurs during the _mlx5_eswitch_set_vepa_locked and mlx5_eswitch_set_vepa functions. To prevent this issue, the system will no longer allow setting or getting the bridge mode when there are no VFs. As a result, the PF interface no longer appears in the 'bridge link' output when there are no VFs.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.