🛡️ CVE-2024-42073 — kernel

🟡 CVSS 5.5 — Medium ✅ No Known Exploit NVD
5.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

mlxsw: spectrum_buffers: Fix memory corruptions on Spectrum-4 systems

In the Linux kernel, the following vulnerability has been resolved:

mlxsw: spectrum_buffers: Fix memory corruptions on Spectrum-4 systems

The following two shared buffer operations make use of the Shared Buffer

Status Register (SBSR):

# devlink sb occupancy snapshot pci/0000:01:00.0

# devlink sb occupancy clearmax pci/0000:01:00.0

The register has two masks of 256 bits to denote on which ingress /

egress ports the register should operate on. Spectrum-4 has more than

256 ports, so the register was extended by cited commit with a new

'port_page' field.

However, when filling the register's payload, the driver specifies the

ports as absolute numbers and not relative to the first port of the port

page, resulting in memory corruptions [1].

Fix by specifying the ports relative to the first port of the port page.

[1]

BUG: KASAN: slab-use-after-free in mlxsw_sp_sb_occ_snapshot+0xb6d/0xbc0

Read of size 1 at addr ffff8881068cb00f by task devlink/1566

[...]

Call Trace:

<TASK>

dump_stack_lvl+0xc6/0x120

print_report+0xce/0x670

kasan_report+0xd7/0x110

mlxsw_sp_sb_occ_snapshot+0xb6d/0xbc0

mlxsw_devlink_sb_occ_snapshot+0x75/0xb0

devlink_nl_sb_occ_snapshot_doit+0x1f9/0x2a0

genl_family_rcv_msg_doit+0x20c/0x300

genl_rcv_msg+0x567/0x800

netlink_rcv_skb+0x170/0x450

genl_rcv+0x2d/0x40

netlink_unicast+0x547/0x830

netlink_sendmsg+0x8d4/0xdb0

__sys_sendto+0x49b/0x510

__x64_sys_sendto+0xe5/0x1c0

do_syscall_64+0xc1/0x1d0

entry_SYSCALL_64_after_hwframe+0x77/0x7f

[...]

Allocated by task 1:

kasan_save_stack+0x33/0x60

kasan_save_track+0x14/0x30

__kasan_kmalloc+0x8f/0xa0

copy_verifier_state+0xbc2/0xfb0

do_check_common+0x2c51/0xc7e0

bpf_check+0x5107/0x9960

bpf_prog_load+0xf0e/0x2690

__sys_bpf+0x1a61/0x49d0

__x64_sys_bpf+0x7d/0xc0

do_syscall_64+0xc1/0x1d0

entry_SYSCALL_64_after_hwframe+0x77/0x7f

Freed by task 1:

kasan_save_stack+0x33/0x60

kasan_save_track+0x14/0x30

kasan_save_free_info+0x3b/0x60

poison_slab_object+0x109/0x170

__kasan_slab_free+0x14/0x30

kfree+0xca/0x2b0

free_verifier_state+0xce/0x270

do_check_common+0x4828/0xc7e0

bpf_check+0x5107/0x9960

bpf_prog_load+0xf0e/0x2690

__sys_bpf+0x1a61/0x49d0

__x64_sys_bpf+0x7d/0xc0

do_syscall_64+0xc1/0x1d0

entry_SYSCALL_64_after_hwframe+0x77/0x7f

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Affected software

CVE-2024-42073 is recorded against 2 packages.

  • kernel (from 6.7.0 up to 6.9.8)
  • linux-kernel (from 6.7 up to 6.9.8)

Timeline and source

Published on 29 July 2024 and last revised on 15 July 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
lists.debian.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2024-42073 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Medium
CVSS Score 5.5
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2024-07-29
Updated 2026-08-12
Modified 2026-07-15

Affected Packages

Software From version Fixed in
kernel 6.7.0 6.9.8
linux-kernel 6.7 6.9.8

Similar Threats

Vulnerability Monitoring

Track new vulnerabilities in kernel

CVE-2024-42073 is rated CVSS 5.5 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2024