{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-50145", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-10-21T19:36:19.956Z", "datePublished": "2024-11-07T09:31:22.202Z", "dateUpdated": "2026-08-05T11:42:01.754Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:42:01.754Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteon_ep: Add SKB allocation failures handling in __octep_oq_process_rx()\n\nbuild_skb() returns NULL in case of a memory allocation failure so handle\nit inside __octep_oq_process_rx() to avoid NULL pointer dereference.\n\n__octep_oq_process_rx() is called during NAPI polling by the driver. If\nskb allocation fails, keep on pulling packets out of the Rx DMA queue: we\nshouldn't break the polling immediately and thus falsely indicate to the\noctep_napi_poll() that the Rx pressure is going down. As there is no\nassociated skb in this case, don't process the packets and don't push them\nup the network stack - they are skipped.\n\nHelper function is implemented to unmmap/flush all the fragment buffers\nused by the dropped packet. 'alloc_failures' counter is incremented to\nmark the skb allocation error in driver statistics.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:N - The vulnerable code is the NIC receive path (`__octep_oq_process_rx()`) invoked from NAPI polling to process network frames delivered by the Marvell Octeon PCIe endpoint NIC, a DPU/SmartNIC deployed on internet-facing cloud servers. A remote attacker reaches the code purely by sending packets to the host, with no local access.\nAC:L - `build_skb()` uses GFP_ATOMIC, which cannot sleep or reclaim and therefore fails readily under the atomic-allocation pressure a high-rate packet flood creates — an attacker can drive this condition with sustained line-rate traffic rather than waiting on it. Since the attacker meaningfully influences the memory-pressure precondition, the lower complexity applies.\nPR:N - The receive path executes in softirq context on every incoming frame with no capability check, no authentication, and no privileged setup step of any kind. An entirely unauthenticated remote sender reaches the vulnerable code.\nUI:N - Packet reception and NAPI polling are fully automatic on any interface that is simply up; no victim action, configuration change, or interaction is required.\nS:U - The NULL dereference faults within the host kernel, and the resulting oops affects only that kernel's own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:N - The fault is a write to a fixed NULL + small-struct-offset address that is unmapped below mmap_min_addr; nothing is read back and no packet or kernel data is disclosed to the attacker.\nI:N - The store target is a constant low address rather than an attacker-influenced pointer, so it faults immediately and modifies no kernel memory — there is no write primitive or control-flow influence.\nA:H - The NULL pointer dereference in `skb_reserve()` triggers a kernel oops in softirq/NAPI context, killing the interrupt thread and the network interface, and causing a full panic on `panic_on_oops` systems typical of embedded, automotive, and appliance deployments." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/ethernet/marvell/octeon_ep/octep_rx.c" ], "versions": [ { "version": "37d79d0596062057f588bdbb2ebad5455a43d353", "lessThan": "09ce491112bbf0b866e2638d3e961c1c73d1f00b", "status": "affected", "versionType": "git" }, { "version": "37d79d0596062057f588bdbb2ebad5455a43d353", "lessThan": "c2d2dc4f88bb3cfc4f3cc320fd3ff51b0ae5b0ea", "status": "affected", "versionType": "git" }, { "version": "37d79d0596062057f588bdbb2ebad5455a43d353", "lessThan": "2dedcb6f99f4c1a11944e7cc35dbeb9b18a5cbac", "status": "affected", "versionType": "git" }, { "version": "37d79d0596062057f588bdbb2ebad5455a43d353", "lessThan": "eb592008f79be52ccef88cd9a5249b3fc0367278", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/ethernet/marvell/octeon_ep/octep_rx.c" ], "versions": [ { "version": "5.19", "status": "affected" }, { "version": "0", "lessThan": "5.19", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.115", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.59", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.11.6", "lessThanOrEqual": "6.11.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.19", "versionEndExcluding": "6.1.115" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.19", "versionEndExcluding": "6.6.59" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.19", "versionEndExcluding": "6.11.6" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.19", "versionEndExcluding": "6.12" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/09ce491112bbf0b866e2638d3e961c1c73d1f00b" }, { "url": "https://git.kernel.org/stable/c/c2d2dc4f88bb3cfc4f3cc320fd3ff51b0ae5b0ea" }, { "url": "https://git.kernel.org/stable/c/2dedcb6f99f4c1a11944e7cc35dbeb9b18a5cbac" }, { "url": "https://git.kernel.org/stable/c/eb592008f79be52ccef88cd9a5249b3fc0367278" } ], "title": "octeon_ep: Add SKB allocation failures handling in __octep_oq_process_rx()", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "cvssV3_1": { "scope": "UNCHANGED", "version": "3.1", "baseScore": 5.5, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "NONE" } }, { "other": { "type": "ssvc", "content": { "id": "CVE-2024-50145", "role": "CISA Coordinator", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "version": "2.0.3", "timestamp": "2025-10-01T20:20:53.967955Z" } } } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "type": "CWE", "cweId": "CWE-476", "description": "CWE-476 NULL Pointer Dereference" } ] } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2025-10-01T20:27:13.740Z" } }, { "title": "CVE Program Container", "references": [ { "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-11-03T22:26:04.314Z" } } ] } }