CVE-2024-41046: net: ethernet: lantiq_etop: fix double free in detach
In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: lantiqetop: fix double free in detach
The number of the currently released descriptor is never incremented which results in the same skb being released multiple times.
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41046?
CVE-2024-41046 has a high severity rating due to a double free vulnerability in the Linux kernel.
How do I fix CVE-2024-41046?
To fix CVE-2024-41046, update your Linux kernel to the latest stable version, such as 5.10.223-1 or higher.
Which versions of the Linux kernel are affected by CVE-2024-41046?
CVE-2024-41046 affects multiple Linux kernel versions between 3.0 and 6.6.41.
What impact does CVE-2024-41046 have on systems?
This vulnerability can lead to unexpected system crashes or potential remote code execution if exploited.
Is there a patch available for CVE-2024-41046?
Yes, patches are available in updated versions of the Linux kernel, such as those released by Debian.