CVE-2024-50206

MEDIUM

Linux Kernel 6.9.6-6.10 - Out-of-bounds Write in MTK Ethernet FQ DMA Initialization

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix memory corruption during fq dma init The loop responsible for allocating up to MTK_FQ_DMA_LENGTH buffers must only touch as many descriptors, otherwise it ends up corrupting unrelated memory. Fix the loop iteration count accordingly.

Scores

CVSS v3 5.5
EPSS 0.0018
EPSS Percentile 7.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (10)
Linux/Linux < 6.10
Linux/Linux 6.10
Linux/Linux 6.11.6 - 6.11.*
Linux/Linux 6.12
Linux/Linux 6.9.6 - 6.10
Linux/Linux 6f50d0bc1bbd45ce2a6d8f378daa00e56c198e9e
Linux/Linux c57e558194430d10d5e5f4acd8a8655b68dade13 - 68cd084e3ec1512cd383cb3e9cf0ab7ab413724c
Linux/Linux c57e558194430d10d5e5f4acd8a8655b68dade13 - 88806efc034a9830f483963326b99930ad519af1
linux/linux_kernel 6.12 rc1 (3 CPE variants)
linux/linux_kernel 6.9.6 - 6.10
Published Nov 08, 2024
Tracked Since Feb 18, 2026