CVE-2024-56656

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Dec 27, 2024
Updated: Jan 6, 2025

Summary

CVE-2024-56656: In the Linux kernel, a vulnerability affecting the bnxt\_en driver on 5760X (P7) chips has been resolved. The issue stems from the redefinition of aggregation ID fields in completion structures, leading to potential misalignment of packet headers. This can result in an "invalid opcode" error, as demonstrated in the provided kernel dump. To mitigate the issue, the aggregation ID mask for P5\_PLUS chips needs to be redefined as 12 bits to accommodate the extra 4 bits used for metadata. This change ensures compatibility and prevents the driver from accessing incorrect TPA buffers.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share