Wind River Support Network

HomeDefectsLIN1023-5669
Fixed

LIN1023-5669 : Security Advisory - linux - CVE-2024-35891

Created: May 19, 2024    Updated: May 22, 2024
Resolved Date: May 19, 2024
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

net: phy: micrel: Fix potential null pointer dereference

In lan8814_get_sig_rx() and lan8814_get_sig_tx() ptp_parse_header() may
return NULL as ptp_header due to abnormal packet type or corrupted packet.
Fix this bug by adding ptp_header check.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

CREATE(Triage):(User=admin) CVE-2024-35891 (https://nvd.nist.gov/vuln/detail/CVE-2024-35891)

CVEs


Live chat
Online