CVE-2024-50208

Source
https://cve.org/CVERecord?id=CVE-2024-50208
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50208.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-50208
Downstream
Related
Published
2024-11-08T06:07:58.607Z
Modified
2026-05-28T03:55:03.412307068Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages

Avoid memory corruption while setting up Level-2 PBL pages for the non MR resources when num_pages > 256K.

There will be a single PDE page address (contiguous pages in the case of > PAGE_SIZE), but, current logic assumes multiple pages, leading to invalid memory access after 256K PBL entries in the PDE.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50208.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0c4dcd602817502bb3dced7a834a13ef717d65a4
Fixed
df6fed0a2a1a5e57f033bca40dc316b18e0d0ce6
Fixed
de5857fa7bcc9a496a914c7e21390be873109f26
Fixed
ea701c1849e7250ea41a4f7493e0a5f136c1d47e
Fixed
87cb3b0054e53e0155b630bdf8fb714ded62565f
Fixed
daac56dd98e1ba814c878ac0acd482a37f2ab94b
Fixed
7988bdbbb85ac85a847baf09879edcd0f70521dc

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50208.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.7.0
Fixed
5.10.229
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.170
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.115
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.59
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.11.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50208.json"