CVE-2024-50206
MEDIUMLinux Kernel 6.9.6-6.10 - Out-of-bounds Write in MTK Ethernet FQ DMA Initialization
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix memory corruption during fq dma init The loop responsible for allocating up to MTK_FQ_DMA_LENGTH buffers must only touch as many descriptors, otherwise it ends up corrupting unrelated memory. Fix the loop iteration count accordingly.
References (2)
Core 2
Scores
CVSS v3
5.5
EPSS
0.0018
EPSS Percentile
7.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-787
Status
published
Products (10)
Linux/Linux
< 6.10
Linux/Linux
6.10
Linux/Linux
6.11.6 - 6.11.*
Linux/Linux
6.12
Linux/Linux
6.9.6 - 6.10
Linux/Linux
6f50d0bc1bbd45ce2a6d8f378daa00e56c198e9e
Linux/Linux
c57e558194430d10d5e5f4acd8a8655b68dade13 - 68cd084e3ec1512cd383cb3e9cf0ab7ab413724c
Linux/Linux
c57e558194430d10d5e5f4acd8a8655b68dade13 - 88806efc034a9830f483963326b99930ad519af1
linux/linux_kernel
6.12 rc1 (3 CPE variants)
linux/linux_kernel
6.9.6 - 6.10
Published
Nov 08, 2024
Tracked Since
Feb 18, 2026