CVE Database
/

CVE-2024-50094

Back to search

CVE-2024-50094

Published: Nov 5, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: sfc: Don't invoke xdp_do_flush() from netpoll. Yury reported a crash in the sfc driver originated from netpoll_send_udp(). The netconsole sends a message and then netpoll invokes the driver's NAPI function with a budget of zero. It is dedicated to allow driver to free TX resources, that it may have used while sending the packet. In the netpoll case the driver invokes xdp_do_flush() unconditionally, leading to crash because bpf_net_context was never assigned. Invoke xdp_do_flush() only if budget is not zero.

VendorProductVersions

Linux

Linux

affected
401cb7dae8130fd34eb84648e02ab4c506df7d5e - < 65d4fc76d75c136744e67754d20feda609e7b793
affected
401cb7dae8130fd34eb84648e02ab4c506df7d5e - < 55e802468e1d38dec8e25a2fdb6078d45b647e8c

Linux

Linux

affected
6.11
unaffected
0 - < 6.11
unaffected
6.11.4 - <= 6.11.*
unaffected
6.12 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now