CVE-2024-56728: octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_ethtool.c
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: handle otx2mboxgetrsp errors in otx2ethtool.c
Add error pointer check after calling otx2mboxgetrsp().
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56728?
CVE-2024-56728 has a medium severity rating due to the potential for exploitation if not properly addressed.
How do I fix CVE-2024-56728?
To fix CVE-2024-56728, update your Linux kernel to a version later than 5.10.231, 5.15.174, 6.1.120, 6.6.64, 6.11.11, or 6.12.2 depending on your current version.
Which versions of the Linux kernel are affected by CVE-2024-56728?
CVE-2024-56728 affects Linux kernel versions between 5.7 and 5.10.231, 5.11 and 5.15.174, 5.16 and 6.1.120, 6.2 and 6.6.64, 6.7 and 6.11.11, and 6.12 and 6.12.2.
What is the nature of the vulnerability CVE-2024-56728?
CVE-2024-56728 is a vulnerability in the Linux kernel related to improper error handling in otx2_ethtool.c when communicating with the otx2 mailbox.
Can CVE-2024-56728 be exploited remotely?
CVE-2024-56728 could potentially be exploited if an attacker can interact with the affected kernel modules, making proper updates essential.