CVE-2024-53120

Source
https://cve.org/CVERecord?id=CVE-2024-53120
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53120.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-53120
Downstream
Related
Published
2024-12-02T13:44:51.098Z
Modified
2026-03-11T07:48:06.112264Z
Summary
net/mlx5e: CT: Fix null-ptr-deref in add rule err flow
Details

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: CT: Fix null-ptr-deref in add rule err flow

In error flow of mlx5tcctentryaddrule(), in case ctruleadd() callback returns error, zonerule->attr is used uninitiated. Fix it to use attr which has the needed pointer value.

Kernel log: BUG: kernel NULL pointer dereference, address: 0000000000000110 RIP: 0010:mlx5tcctentryaddrule+0x2b1/0x2f0 [mlx5core] … Call Trace: <TASK> ? __die+0x20/0x70 ? pagefaultoops+0x150/0x3e0 ? exc_pagefault+0x74/0x140 ? asmexcpagefault+0x22/0x30 ? mlx5tcctentryaddrule+0x2b1/0x2f0 [mlx5core] ? mlx5tcctentryaddrule+0x1d5/0x2f0 [mlx5core] mlx5tcctblockflowoffload+0xc6a/0xf90 [mlx5core] ? nfflowoffloadtuple+0xd8/0x190 [nfflowtable] nfflowoffloadtuple+0xd8/0x190 [nfflowtable] flowoffloadworkhandler+0x142/0x320 [nfflowtable] ? finishtaskswitch.isra.0+0x15b/0x2b0 processonework+0x16c/0x320 workerthread+0x28c/0x3a0 ? __pfxworkerthread+0x10/0x10 kthread+0xb8/0xf0 ? __pfxkthread+0x10/0x10 retfrom_fork+0x2d/0x50 ? __pfxkthread+0x10/0x10 retfromforkasm+0x1a/0x30 </TASK>

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/53xxx/CVE-2024-53120.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7fac5c2eced36f335ee19ff316bd3182fbeda823
Fixed
882f392d9e3649557e71efd78ae20c86039ffb7c
Fixed
0c7c70ff8b696cfedba350411dca736361ef9a0f
Fixed
06dc488a593020bd2f006798557d2a32104d8359
Fixed
6030f8bd7902e9e276a0edc09bf11979e4e2bc2e
Fixed
e99c6873229fe0482e7ceb7d5600e32d623ed9d9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53120.json"