bnx2x: Fix multiple UBSAN array-index-out-of-bounds
In the Linux kernel, the following vulnerability has been resolved: bnx2x: Fix multiple UBSAN array-index-out-of-bounds Fix UBSAN warnings that occur when using a system with 32 physical cpu cores or more, or when the user defines a number of Ethernet queues greater than or equal to FP_SB_MAX_E1x using the num_queues module parameter. Currently there is a read/write out of bounds that occurs on the array "struct stats_query_entry query" present inside the "bnx2x_fw_stats_req" struct in "drivers/net/ethernet/broadcom/bnx2x/bnx2x.h". Looking at the definition of the "struct stats_query_entry query" array: struct stats_query_entry query[FP_SB_MAX_E1x+ BNX2X_FIRST_QUEUE_QUERY_IDX]; FP_SB_MAX_E1x is defined as the maximum number of fast path interrupts and has a value of 16, while BNX2X_FIRST_QUEUE_QUERY_IDX has a value of 3 meaning the array has a total size of 19. Since accesses to "struct stats_query_entry query" are offset-ted by BNX2X_FIRST_QUEUE_QUERY_IDX, that means that the total number of Ethernet queues should not exceed FP_SB_MAX_E1x (16). However one of these queues is reserved for FCOE and thus the number of Ethernet queues should be set to [FP_SB_MAX_E1x -1] (15) if FCOE is enabled or [FP_SB_MAX_E1x] (16) if it is not. This is also described in a comment in the source code in drivers/net/ethernet/broadcom/bnx2x/bnx2x.h just above the Macro definition of FP_SB_MAX_E1x. Below is the part of this explanation that it important for this patch /* * The total number of L2 queues, MSIX vectors and HW contexts (CIDs) is * control by the number of fast-path status blocks supported by the * device (HW/FW). Each fast-path status block (FP-SB) aka non-default * status block represents an independent interrupts context that can * serve a regular L2 networking queue. However special L2 queues such * as the FCoE queue do not require a FP-SB and other components like * the CNIC may consume FP-SB reducing the number of possible L2 queues * * If the maximum number of FP-SB available is X then: * a. If CNIC is supported it consumes 1 FP-SB thus the max number of * regular L2 queues is Y=X-1 * b. In MF mode the actual number of L2 queues is Y= (X-1/MF_factor) * c. If the FCoE L2 queue is supported the actual number of L2 queues * is Y+1 * d. The number of irqs (MSIX vectors) is either Y+1 (one extra for * slow-path interrupts) or Y+2 if CNIC is supported (one additional * FP interrupt context for the CNIC). * e. The number of HW context (CID count) is always X or X+1 if FCoE * L2 queue is supported. The cid for the FCoE L2 queue is always X. */ However this driver also supports NICs that use the E2 controller which can handle more queues due to having more FP-SB represented by FP_SB_MAX_E2. Looking at the commits when the E2 support was added, it was originally using the E1x parameters: commit f2e0899f0f27 ("bnx2x: Add 57712 support"). Back then FP_SB_MAX_E2 was set to 16 the same as E1x. However the driver was later updated to take full advantage of the E2 instead of having it be limited to the capabilities of the E1x. But as far as we can tell, the array "stats_query_entry query" was still limited to using the FP-SB available to the E1x cards as part of an oversignt when the driver was updated to take full advantage of the E2, and now with the driver being aware of the greater queue size supported by E2 NICs, it causes the UBSAN warnings seen in the stack traces below. This patch increases the size of the "stats_query_entry query" array by replacing FP_SB_MAX_E1x with FP_SB_MAX_E2 to be large enough to handle both types of NICs. Stack traces: UBSAN: array-index-out-of-bounds in drivers/net/ethernet/broadcom/bnx2x/bnx2x_stats.c:1529:11 index 20 is out of range for type 'stats_query_entry [19]' CPU: 12 PID: 858 Comm: systemd-network Not tainted 6.9.0-060900rc7-generic #202405052133 Hardware name: HP ProLiant DL360 Gen9/ProLiant DL360 ---truncated---
- Yayın
- 30 Tem 2024
- Güncelleme
- 17 Haz 2026
- EPSS
- %0,3 · 16. yüzdelik
- CWE
- CWE-129
Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.
Rapor araçları
Aksiyon skoru
31
İzleyin
Şimdilik düşük öncelik.
- CVSS
- 31 / 40 · 7.8 / 10
- CISA KEV
- 0 / 30 · Listede değil
- EPSS
- 0 / 30 · %0,3
CISA SSVC kararı
- Sömürü
- yok
- Otomatikleştirilebilir
- hayır
- Teknik etki
- kısmi
Vulnrichment: CISA'nın karar ağacı girdileri.
Noroxi analizi
Bu kayıt için henüz Noroxi analizi yok
Veritabanındaki yüz binlerce zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.
Bu ürünü kullanıyoruz, yardım isteyinEtkilenen sistemler
| Üretici | Ürün | CPE |
|---|---|---|
| linux | linux kernel | cpe:2.3:o:linux:linux_kernel |
Etkilenen sürümler
NVD sürüm aralıkları (katalogdaki ürünler için). Stack’ine sürümle eklersen eşleşme bunlarla yapılır.
- linux linux kernel3.3 ve sonrası · 4.19.318 öncesi
- linux linux kernel4.20 ve sonrası · 5.4.280 öncesi
- linux linux kernel5.5 ve sonrası · 5.10.222 öncesi
- linux linux kernel5.11 ve sonrası · 5.15.163 öncesi
- linux linux kernel5.16 ve sonrası · 6.1.98 öncesi
- linux linux kernel6.2 ve sonrası · 6.6.39 öncesi
- linux linux kernel6.7 ve sonrası · 6.9.9 öncesi
Üreticinin bildirdiği sürümler
Kaydı açan otorite (Linux) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.
Linux Linux
- 3.3etkilenir
- 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · cfb04472ce33bee2579caf4dc9f4242522f6e26e öncesietkilenir · git
- 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · cbe53087026ad929cd3950508397e8892a6a2a0f öncesietkilenir · git
- 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · 8b17cec33892a66bbd71f8d9a70a45e2072ae84f öncesietkilenir · git
- 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · 0edae06b4c227bcfaf3ce21208d49191e1009d3b öncesietkilenir · git
- 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · 9504a1550686f53b0bab4cab31d435383b1ee2ce öncesietkilenir · git
- 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · f1313ea92f82451923e28ab45a4aaa0e70e80b98 öncesietkilenir · git
- 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · b9ea38e767459111a511ed4fb74abc37db95a59d öncesietkilenir · git
- 50f0a562f8cc9ed9d9f7f7380434c3c8646172d5 ve sonrası · 134061163ee5ca4759de5c24ca3bd71608891ba7 öncesietkilenir · git
- 3.3 öncesietkilenmez · semver
Paket düzeyi etkilenme
OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.
| Ekosistem | Paket | Etkilenen aralık | Düzeltme |
|---|---|---|---|
| Debian:12 | linux | 6.1.98-1 öncesi | 6.1.98-1 |
| Debian:13 | linux | 6.9.9-1 öncesi | 6.9.9-1 |
| SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE | kernel-default | 3.0.101-108.165.1 öncesi | 3.0.101-108.165.1 |
| SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE | kernel-ec2 | 3.0.101-108.165.1 öncesi | 3.0.101-108.165.1 |
| SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE | kernel-source | 3.0.101-108.165.1 öncesi | 3.0.101-108.165.1 |
| SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE | kernel-syms | 3.0.101-108.165.1 öncesi | 3.0.101-108.165.1 |
| SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE | kernel-trace | 3.0.101-108.165.1 öncesi | 3.0.101-108.165.1 |
| SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE | kernel-xen | 3.0.101-108.165.1 öncesi | 3.0.101-108.165.1 |
Aynı üründe
linux: tüm kayıtlarAynı birincil ürünün en yüksek skorlu diğer kayıtları.
- CVE-2022-0847A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe KEV89Hemen
- CVE-2021-22555Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACEKEV85Hemen
- CVE-2016-5195Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect haKEV83Hemen
- CVE-2019-13272In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to creKEV77Bu hafta
- CVE-2013-6282The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addKEV77Bu hafta
- CVE-2013-2094The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows loKEV77Bu hafta
Düzeltme
Hangi sürüme geçmeli
Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.
| Ürün / paket | Düzeltilmiş sürüm | Kaynak |
|---|---|---|
| Linux Linux | 0edae06b4c227bcfaf3ce21208d49191e1009d3b | Üretici (CNA) |
| Linux Linux | 134061163ee5ca4759de5c24ca3bd71608891ba7 | Üretici (CNA) |
| Linux Linux | 8b17cec33892a66bbd71f8d9a70a45e2072ae84f | Üretici (CNA) |
| Linux Linux | 9504a1550686f53b0bab4cab31d435383b1ee2ce | Üretici (CNA) |
| Linux Linux | b9ea38e767459111a511ed4fb74abc37db95a59d | Üretici (CNA) |
| Linux Linux | cbe53087026ad929cd3950508397e8892a6a2a0f | Üretici (CNA) |
| Linux Linux | cfb04472ce33bee2579caf4dc9f4242522f6e26e | Üretici (CNA) |
| Linux Linux | f1313ea92f82451923e28ab45a4aaa0e70e80b98 | Üretici (CNA) |
| debian:linux | 6.1.98-1 · Debian:12 | Paket deposu (OSV) |
| suse:kernel-default | 3.0.101-108.165.1 · SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE | Paket deposu (OSV) |
| suse:kernel-ec2 | 3.0.101-108.165.1 · SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE | Paket deposu (OSV) |
| suse:kernel-source | 3.0.101-108.165.1 · SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE | Paket deposu (OSV) |
| suse:kernel-syms | 3.0.101-108.165.1 · SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE | Paket deposu (OSV) |
| suse:kernel-trace | 3.0.101-108.165.1 · SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE | Paket deposu (OSV) |
| suse:kernel-xen | 3.0.101-108.165.1 · SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE | Paket deposu (OSV) |
İstismar durumu
Bilinen kamuya açık istismar yok
Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.
Araştırma bağlamı
Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.
Zaman çizelgesi
Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.
Yayın dışında tarihli olay yok.
FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).
Yama ve commit bağlantıları
Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.
Referanslarda commit ya da PR bağlantısı yok.
Kredi
Tüm araştırmacılarCNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.
CNA kaydında kredi yok.
Varyant adayları
Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.
- CVE-2021-4754867 gün araylaethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port()39İzleyin
- CVE-2023-2008473 gün araylaKernel: udmabuf: improper validation of array index leading to local privilege escalation32İzleyin
- CVE-2024-421170 gün arayladrm/amd/display: ASSERT when failing to find index by plane/stream id31İzleyin
- CVE-2024-421200 gün arayladrm/amd/display: Check pipe offset before setting vblank31İzleyin
- CVE-2024-421210 gün arayladrm/amd/display: Check index msg_id before read or write31İzleyin
- CVE-2024-420881 gün araylaASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link31İzleyin
Zincir adayları
Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.
—
Bug bounty kapsamı
Bilinen herkese açık program yok.
Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).
Ulusal bildirim (Siber Güvenlik Başkanlığı / USOM)
Bu kaydı anan resmi güvenlik bildirimleri; çözüm önerisi kurumun sayfasında.
- TR-24-1106 · 31 Tem 2024(Linux Kernel Güncellemesi)
Teknik detay
Saldırı koşulları
- Sisteme yerel erişimi olan biri tetikleyebilir.
- Düşük yetkili bir hesap yeterli.
- Kullanıcının bir şey yapması gerekmez.
- Özel bir koşul gerekmez; tekrarlanabilir.
Başarılı olursa
- Gizlilik
- yüksek · veriler okunabilir
- Bütünlük
- yüksek · veri ya da yapılandırma değiştirilebilir
- Erişilebilirlik
- yüksek · hizmet durdurulabilir
- Saldırı vektörü
- Yerel
- Karmaşıklık
- Düşük
- Gereken yetki
- Düşük
- Kullanıcı etkileşimi
- Gerekmez
- Kapsam
- Değişmez
- Gizlilik etkisi
- Yüksek
- Bütünlük etkisi
- Yüksek
- Erişilebilirlik etkisi
- Yüksek
Zayıflık sınıfı (CWE)
CWE-129 · Improper Validation of Array IndexCVSS vektörü
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd-primary
Saldırı bağlamı
Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.
Saldırı desenleri (CAPEC)
ATT&CK teknikleri
—
Değişiklik günlüğü
- Düzeltme✗ → ✓
Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →
Referanslar
- git.kernel.org/stable/c/0edae06b4c227bcfaf3ce21208d49191e1009d3b
- git.kernel.org/stable/c/134061163ee5ca4759de5c24ca3bd71608891ba7
- git.kernel.org/stable/c/8b17cec33892a66bbd71f8d9a70a45e2072ae84f
- git.kernel.org/stable/c/9504a1550686f53b0bab4cab31d435383b1ee2ce
- git.kernel.org/stable/c/b9ea38e767459111a511ed4fb74abc37db95a59d
- git.kernel.org/stable/c/cbe53087026ad929cd3950508397e8892a6a2a0f
- git.kernel.org/stable/c/cfb04472ce33bee2579caf4dc9f4242522f6e26e
- git.kernel.org/stable/c/f1313ea92f82451923e28ab45a4aaa0e70e80b98
- lists.debian.org/debian-lts-announce/2025/01/msg00001.html
Üretici bildirimleri ve resmî kayıtlar. İstismar/PoC bağlantıları bilinçli olarak dışarıda bırakıldı.