CVE-2024-40919

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-40919
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-40919.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-40919
Downstream
Related
Published
2024-07-12T13:15:14Z
Modified
2025-08-09T20:01:27Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

bnxten: Adjust logging of firmware messages in case of released token in _hwrm_send()

In case of token is released due to token->state == BNXTHWRMDEFERRED, released token (set to NULL) is used in log messages. This issue is expected to be prevented by HWRMERRCODEPFUNAVAILABLE error code. But this error code is returned by recent firmware. So some firmware may not return it. This may lead to NULL pointer dereference. Adjust this issue by adding token pointer check.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

References

Affected packages