CVE-2024-26858

Analyzed
Published: 17 Apr 2024, 10:17
Last modified:23 May 2026, 15:39

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.01% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Apr 2024, 10:17
Published
Vulnerability first disclosed
23 May 2026, 15:39
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Use a memory barrier to enforce PTP WQ xmit submission tracking occurs after populating the metadata_map Just simply reordering the functions mlx5e_ptp_metadata_map_put and mlx5e_ptpsq_track_metadata in the mlx5e_txwqe_complete context is not good enough since both the compiler and CPU are free to reorder these two functions. If reordering does occur, the issue that was supposedly fixed by 7e3f3ba97e6c ("net/mlx5e: Track xmit submission to PTP WQ after populating metadata map") will be seen. This will lead to NULL pointer dereferences in mlx5e_ptpsq_mark_ts_cqes_undelivered in the NAPI polling context due to the tracking list being populated before the metadata map.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.01% Percentile: 3%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • linuxlinux

    ≥ 4d510506b46504664eacf8a44a9e8f3e54c137b8, < d1f71615dbb305f14f3b756cce015d70d8667549 | ≥ 7e3f3ba97e6cc6fce5bf62df2ca06c8e59040167, < 936ef086161ab89a7f38f7a0761d6a3063c3277e | ≥ 7e3f3ba97e6cc6fce5bf62df2ca06c8e59040167, < b7cf07586c40f926063d4d09f7de28ff82f62b2a | a9d6c0c5a6bd9ca88e964f8843ea41bc085de866 | ≥ 6.6.3, < 6.6.22 | ≥ 6.5.13, < 6.6 | 6.7

  • linuxlinux_kernel

    ≥ 6.5.13, < 6.6 | ≥ 6.6.3, < 6.6.22 | ≥ 6.7, < 6.7.10 | 6.8:rc1 | 6.8:rc2 | 6.8:rc3 | 6.8:rc4 | 6.8:rc5 | 6.8:rc6 | 6.8:rc7

References (3)