CVE-2024-46861
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Sep 27, 2024
Updated: Oct 3, 2024
Summary
CVE-2024-46861 is a vulnerability affecting the Linux kernel's usbnet driver. The issue lies in the ipheth subdriver where RX callback failures are not handled appropriately. Such failures can occur due to various reasons, including payloads that are too short or incorrectly formatted, or a lack of memory. Contrary to expectation, these failures should not cause the driver to seize up. Instead, the driver needs to be modified to treat these failures as non-critical and continue processing incoming URBs ( Ursbs (USB Requests) ).
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.