CVE-2024-44988: net: dsa: mv88e6xxx: Fix out-of-bound access
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: mv88e6xxx: Fix out-of-bound access
If an ATU violation was caused by a CPU Load operation, the SPID could be larger than DSAMAXPORTS (the size of mv88e6xxxchip.ports[] array).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44988?
CVE-2024-44988 has a severity rating that may vary based on the deployment context, but it is categorized as an out-of-bound access vulnerability in the Linux kernel.
How do I fix CVE-2024-44988?
To fix CVE-2024-44988, you should upgrade to the patched versions listed, such as linux version 5.10.226-1 or later.
Which Linux kernel versions are affected by CVE-2024-44988?
CVE-2024-44988 affects Linux kernel versions between 4.19.21 and 6.11-rc4, specifically those versions that fall within this range.
What is the impact of CVE-2024-44988?
The impact of CVE-2024-44988 includes potential out-of-bound memory access, which could lead to system instability or compromise if exploited.
Is there a workaround for CVE-2024-44988?
There is no official workaround for CVE-2024-44988; the recommended action is to update the kernel to a non-vulnerable version.