CVE-2024-50094
Published: Nov 5, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: sfc: Don't invoke xdp_do_flush() from netpoll. Yury reported a crash in the sfc driver originated from netpoll_send_udp(). The netconsole sends a message and then netpoll invokes the driver's NAPI function with a budget of zero. It is dedicated to allow driver to free TX resources, that it may have used while sending the packet. In the netpoll case the driver invokes xdp_do_flush() unconditionally, leading to crash because bpf_net_context was never assigned. Invoke xdp_do_flush() only if budget is not zero.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 401cb7dae8130fd34eb84648e02ab4c506df7d5e - < 65d4fc76d75c136744e67754d20feda609e7b793affected 401cb7dae8130fd34eb84648e02ab4c506df7d5e - < 55e802468e1d38dec8e25a2fdb6078d45b647e8c |
Linux | Linux | affected 6.11unaffected 0 - < 6.11unaffected 6.11.4 - <= 6.11.*unaffected 6.12 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now