CVE-2024-56649
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-56649 is a vulnerability affecting the Linux kernel's ENETC driver, specifically the VF variant. The issue arises from a function, enetic_setup_tc_mqprio(), that attempts to configure preemptible traffic control classes (TCs) for VFs. However, VFs do not have the necessary registers to support preemptible TCs, leading to an invalid memory access and a crash. This vulnerability is not limited to certain PFs, but some, such as eno1 and eno3 on LS1028A, do not support preemptible TCs at all. To mitigate this issue, it is recommended to prevent unsupported PFs from attempting to access these unimplemented registers.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX