İçeriğe atla
Noroxi
CVE-2024-42148· NVD / CVE Programı· CNA Linux

bnx2x: Fix multiple UBSAN array-index-out-of-bounds

In the Linux kernel, the following vulnerability has been resolved: bnx2x: Fix multiple UBSAN array-index-out-of-bounds Fix UBSAN warnings that occur when using a system with 32 physical cpu cores or more, or when the user defines a number of Ethernet queues greater than or equal to FP_SB_MAX_E1x using the num_queues module parameter. Currently there is a read/write out of bounds that occurs on the array "struct stats_query_entry query" present inside the "bnx2x_fw_stats_req" struct in "drivers/net/ethernet/broadcom/bnx2x/bnx2x.h". Looking at the definition of the "struct stats_query_entry query" array: struct stats_query_entry query[FP_SB_MAX_E1x+ BNX2X_FIRST_QUEUE_QUERY_IDX]; FP_SB_MAX_E1x is defined as the maximum number of fast path interrupts and has a value of 16, while BNX2X_FIRST_QUEUE_QUERY_IDX has a value of 3 meaning the array has a total size of 19. Since accesses to "struct stats_query_entry query" are offset-ted by BNX2X_FIRST_QUEUE_QUERY_IDX, that means that the total number of Ethernet queues should not exceed FP_SB_MAX_E1x (16). However one of these queues is reserved for FCOE and thus the number of Ethernet queues should be set to [FP_SB_MAX_E1x -1] (15) if FCOE is enabled or [FP_SB_MAX_E1x] (16) if it is not. This is also described in a comment in the source code in drivers/net/ethernet/broadcom/bnx2x/bnx2x.h just above the Macro definition of FP_SB_MAX_E1x. Below is the part of this explanation that it important for this patch /* * The total number of L2 queues, MSIX vectors and HW contexts (CIDs) is * control by the number of fast-path status blocks supported by the * device (HW/FW). Each fast-path status block (FP-SB) aka non-default * status block represents an independent interrupts context that can * serve a regular L2 networking queue. However special L2 queues such * as the FCoE queue do not require a FP-SB and other components like * the CNIC may consume FP-SB reducing the number of possible L2 queues * * If the maximum number of FP-SB available is X then: * a. If CNIC is supported it consumes 1 FP-SB thus the max number of * regular L2 queues is Y=X-1 * b. In MF mode the actual number of L2 queues is Y= (X-1/MF_factor) * c. If the FCoE L2 queue is supported the actual number of L2 queues * is Y+1 * d. The number of irqs (MSIX vectors) is either Y+1 (one extra for * slow-path interrupts) or Y+2 if CNIC is supported (one additional * FP interrupt context for the CNIC). * e. The number of HW context (CID count) is always X or X+1 if FCoE * L2 queue is supported. The cid for the FCoE L2 queue is always X. */ However this driver also supports NICs that use the E2 controller which can handle more queues due to having more FP-SB represented by FP_SB_MAX_E2. Looking at the commits when the E2 support was added, it was originally using the E1x parameters: commit f2e0899f0f27 ("bnx2x: Add 57712 support"). Back then FP_SB_MAX_E2 was set to 16 the same as E1x. However the driver was later updated to take full advantage of the E2 instead of having it be limited to the capabilities of the E1x. But as far as we can tell, the array "stats_query_entry query" was still limited to using the FP-SB available to the E1x cards as part of an oversignt when the driver was updated to take full advantage of the E2, and now with the driver being aware of the greater queue size supported by E2 NICs, it causes the UBSAN warnings seen in the stack traces below. This patch increases the size of the "stats_query_entry query" array by replacing FP_SB_MAX_E1x with FP_SB_MAX_E2 to be large enough to handle both types of NICs. Stack traces: UBSAN: array-index-out-of-bounds in drivers/net/ethernet/broadcom/bnx2x/bnx2x_stats.c:1529:11 index 20 is out of range for type 'stats_query_entry [19]' CPU: 12 PID: 858 Comm: systemd-network Not tainted 6.9.0-060900rc7-generic #202405052133 Hardware name: HP ProLiant DL360 Gen9/ProLiant DL360 ---truncated---

YüksekCVSS 7.8 · v3.1—İstismar yok Düzeltme var
Yayın
30 Tem 2024
Güncelleme
17 Haz 2026
EPSS
%0,3 · 16. yüzdelik
Bu CVE’yi takip et

Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.

Rapor araçları

JSON

Aksiyon skoru

31

İzleyin

Şimdilik düşük öncelik.

CVSS
31 / 40 · 7.8 / 10
CISA KEV
0 / 30 · Listede değil
EPSS
0 / 30 · %0,3

CISA SSVC kararı

Sömürü
yok
Otomatikleştirilebilir
hayır
Teknik etki
kısmi

Vulnrichment: CISA'nın karar ağacı girdileri.

Noroxi analizi

Bu kayıt için henüz Noroxi analizi yok

Veritabanındaki yüz binlerce zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.

Bu ürünü kullanıyoruz, yardım isteyin

Etkilenen sistemler

ÜreticiÜrün
linuxlinux kernel

Etkilenen sürümler

NVD sürüm aralıkları (katalogdaki ürünler için). Stack’ine sürümle eklersen eşleşme bunlarla yapılır.

  • linux linux kernel3.3 ve sonrası · 4.19.318 öncesi
  • linux linux kernel4.20 ve sonrası · 5.4.280 öncesi
  • linux linux kernel5.5 ve sonrası · 5.10.222 öncesi
  • linux linux kernel5.11 ve sonrası · 5.15.163 öncesi
  • linux linux kernel5.16 ve sonrası · 6.1.98 öncesi
  • linux linux kernel6.2 ve sonrası · 6.6.39 öncesi
  • linux linux kernel6.7 ve sonrası · 6.9.9 öncesi

Üreticinin bildirdiği sürümler

Kaydı açan otorite (Linux) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.

  • Linux Linux

    • 3.3etkilenir
    • 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · cfb04472ce33bee2579caf4dc9f4242522f6e26e öncesietkilenir · git
    • 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · cbe53087026ad929cd3950508397e8892a6a2a0f öncesietkilenir · git
    • 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · 8b17cec33892a66bbd71f8d9a70a45e2072ae84f öncesietkilenir · git
    • 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · 0edae06b4c227bcfaf3ce21208d49191e1009d3b öncesietkilenir · git
    • 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · 9504a1550686f53b0bab4cab31d435383b1ee2ce öncesietkilenir · git
    • 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · f1313ea92f82451923e28ab45a4aaa0e70e80b98 öncesietkilenir · git
    • 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · b9ea38e767459111a511ed4fb74abc37db95a59d öncesietkilenir · git
    • 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · 134061163ee5ca4759de5c24ca3bd71608891ba7 öncesietkilenir · git
    • 3.3 öncesietkilenmez · semver

Paket düzeyi etkilenme

OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.

EkosistemPaketEtkilenen aralıkDüzeltme
Debian:12linux6.1.98-1 öncesi6.1.98-1
Debian:13linux6.9.9-1 öncesi6.9.9-1
SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME COREkernel-default3.0.101-108.165.1 öncesi3.0.101-108.165.1
SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME COREkernel-ec23.0.101-108.165.1 öncesi3.0.101-108.165.1
SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME COREkernel-source3.0.101-108.165.1 öncesi3.0.101-108.165.1
SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME COREkernel-syms3.0.101-108.165.1 öncesi3.0.101-108.165.1
SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME COREkernel-trace3.0.101-108.165.1 öncesi3.0.101-108.165.1
SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME COREkernel-xen3.0.101-108.165.1 öncesi3.0.101-108.165.1

Aynı birincil ürünün en yüksek skorlu diğer kayıtları.

  • CVE-2022-0847A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe KEV
    89Hemen
  • CVE-2021-22555Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACEKEV
    85Hemen
  • CVE-2016-5195Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect haKEV
    83Hemen
  • CVE-2019-13272In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to creKEV
    77Bu hafta
  • CVE-2013-6282The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addKEV
    77Bu hafta
  • CVE-2013-2094The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows loKEV
    77Bu hafta

Düzeltme

Hangi sürüme geçmeli

Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.

Ürün / paketDüzeltilmiş sürümKaynak
Linux Linux0edae06b4c227bcfaf3ce21208d49191e1009d3bÜretici (CNA)
Linux Linux134061163ee5ca4759de5c24ca3bd71608891ba7Üretici (CNA)
Linux Linux8b17cec33892a66bbd71f8d9a70a45e2072ae84fÜretici (CNA)
Linux Linux9504a1550686f53b0bab4cab31d435383b1ee2ceÜretici (CNA)
Linux Linuxb9ea38e767459111a511ed4fb74abc37db95a59dÜretici (CNA)
Linux Linuxcbe53087026ad929cd3950508397e8892a6a2a0fÜretici (CNA)
Linux Linuxcfb04472ce33bee2579caf4dc9f4242522f6e26eÜretici (CNA)
Linux Linuxf1313ea92f82451923e28ab45a4aaa0e70e80b98Üretici (CNA)
debian:linux6.1.98-1 · Debian:12Paket deposu (OSV)
suse:kernel-default3.0.101-108.165.1 · SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME COREPaket deposu (OSV)
suse:kernel-ec23.0.101-108.165.1 · SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME COREPaket deposu (OSV)
suse:kernel-source3.0.101-108.165.1 · SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME COREPaket deposu (OSV)
suse:kernel-syms3.0.101-108.165.1 · SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME COREPaket deposu (OSV)
suse:kernel-trace3.0.101-108.165.1 · SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME COREPaket deposu (OSV)
suse:kernel-xen3.0.101-108.165.1 · SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME COREPaket deposu (OSV)

İstismar durumu

Bilinen kamuya açık istismar yok

Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.

Araştırma bağlamı

Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.

Zaman çizelgesi

Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.

Yayın dışında tarihli olay yok.

EPSS son 120 gün

FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).

Yama ve commit bağlantıları

Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.

Referanslarda commit ya da PR bağlantısı yok.

CNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.

CNA kaydında kredi yok.

Varyant adayları

Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.

  • CVE-2021-4754867 gün araylaethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port()
    39İzleyin
  • CVE-2023-2008473 gün araylaKernel: udmabuf: improper validation of array index leading to local privilege escalation
    32İzleyin
  • CVE-2024-421170 gün arayladrm/amd/display: ASSERT when failing to find index by plane/stream id
    31İzleyin
  • CVE-2024-421200 gün arayladrm/amd/display: Check pipe offset before setting vblank
    31İzleyin
  • CVE-2024-421210 gün arayladrm/amd/display: Check index msg_id before read or write
    31İzleyin
  • CVE-2024-420881 gün araylaASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link
    31İzleyin

Zincir adayları

Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.

—

Bug bounty kapsamı

Bilinen herkese açık program yok.

Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).

Ulusal bildirim (Siber Güvenlik Başkanlığı / USOM)

Bu kaydı anan resmi güvenlik bildirimleri; çözüm önerisi kurumun sayfasında.

Tüm ulusal bildirimler →

Teknik detay

Saldırı koşulları

  • Sisteme yerel erişimi olan biri tetikleyebilir.
  • Düşük yetkili bir hesap yeterli.
  • Kullanıcının bir şey yapması gerekmez.
  • Özel bir koşul gerekmez; tekrarlanabilir.

Başarılı olursa

Gizlilik
yüksek · veriler okunabilir
Bütünlük
yüksek · veri ya da yapılandırma değiştirilebilir
Erişilebilirlik
yüksek · hizmet durdurulabilir
Saldırı vektörü
Yerel
Karmaşıklık
Düşük
Gereken yetki
Düşük
Kullanıcı etkileşimi
Gerekmez
Kapsam
Değişmez
Gizlilik etkisi
Yüksek
Bütünlük etkisi
Yüksek
Erişilebilirlik etkisi
Yüksek

CVSS vektörü

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

nvd-primary

Saldırı bağlamı

Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.

ATT&CK teknikleri

—

Değişiklik günlüğü

  1. Düzeltme✗ → ✓

Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →

Referanslar

Tüm kayıtlar