Fiche vulnérabilité
CVE-2024-53043 : faille moyenne linux linux kernel (CVSS 5.5)
Description
In the Linux kernel, the following vulnerability has been resolved: mctp i2c: handle NULL header address daddr can be NULL if there is no neighbour table entry present, in that case the tx packet should be dropped. saddr will usually be set by MCTP core, but check for NULL in case a packet is transmitted by a different protocol.
En bref
- Sévérité
- Moyenne (CVSS 5.5)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 19 nov. 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- linux linux kernel
Références
- Fiche CVE-2024-53043 sur le NVD (NIST)
- git.kernel.org/stable/c/01e215975fd80af81b5b79f009d49ddd35976…
- git.kernel.org/stable/c/4707893315802a0917231b94cb20cbe50ccbf…
- git.kernel.org/stable/c/8c222adadc1612e4f097688875962a28e3f5a…
- git.kernel.org/stable/c/8e886e44397ba89f6e8da8471386112b4f5b6…
- lists.debian.org/debian-lts-announce/2025/01/msg00001.html