CVE-2024-42162 (GCVE-0-2024-42162)
Vulnerability from cvelistv5
Published
2024-07-30 07:47
Modified
2026-08-05 11:35
Summary
In the Linux kernel, the following vulnerability has been resolved: gve: Account for stopped queues when reading NIC stats We now account for the fact that the NIC might send us stats for a subset of queues. Without this change, gve_get_ethtool_stats might make an invalid access on the priv->stats_report->stats array.
Impacted products
Vendor Product Version
Linux Linux Version: 2f523dc34ac8c355609e9b847852bf25bbdb30bf
Version: 2f523dc34ac8c355609e9b847852bf25bbdb30bf
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T04:54:32.609Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/32675d828c8a392e20d5b42375ed112c407e4b62"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/af9bcf910b1f86244f39e15e701b2dc564b469a6"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-42162",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T16:14:49.244034Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:33:07.261Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/google/gve/gve_ethtool.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "32675d828c8a392e20d5b42375ed112c407e4b62",
              "status": "affected",
              "version": "2f523dc34ac8c355609e9b847852bf25bbdb30bf",
              "versionType": "git"
            },
            {
              "lessThan": "af9bcf910b1f86244f39e15e701b2dc564b469a6",
              "status": "affected",
              "version": "2f523dc34ac8c355609e9b847852bf25bbdb30bf",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/google/gve/gve_ethtool.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.10"
            },
            {
              "lessThan": "5.10",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.9.*",
              "status": "unaffected",
              "version": "6.9.9",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.10",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9.9",
                  "versionStartIncluding": "5.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10",
                  "versionStartIncluding": "5.10",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngve: Account for stopped queues when reading NIC stats\n\nWe now account for the fact that the NIC might send us stats for a\nsubset of queues. Without this change, gve_get_ethtool_stats might make\nan invalid access on the priv-\u003estats_report-\u003estats array."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code is reached through the `SIOCETHTOOL`/`ETHTOOL_GSTATS` ioctl on a local netdev, requiring local system access. There is no remote or adjacent-network path into `gve_get_ethtool_stats()`.\nAC:L - The attacker can invoke `ethtool -S` an unlimited number of times with no rate limit, and because the out-of-bounds index comes from an uninitialized small kmalloc allocation, standard slab grooming lets the attacker place chosen values there, making the OOB access reliable and repeatable rather than dependent on chance.\nPR:L - `ETHTOOL_GSTATS` is explicitly listed among the ethtool commands \"allowed to be done by anyone\" in `__dev_ethtool()`, bypassing the `ns_capable(CAP_NET_ADMIN)` check, so only an ordinary unprivileged local account is needed.\nUI:N - The attacker triggers the entire flow themselves with a single ioctl; no action by any other user or administrator is required.\nS:U - The out-of-bounds read and write are confined to kernel memory within the same security authority as the kernel itself, with no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - Four `u64` words per affected queue are read from an uncontrolled/groomable offset outside the `priv-\u003estats_report-\u003estats` DMA buffer and copied straight to userspace by `ethtool_get_stats()`, yielding disclosure of arbitrary kernel memory including pointers and secrets.\nI:H - The unvalidated device-supplied `queue_id` is used directly as an index in `rx_qid_to_stats_idx[queue_id] = stats_idx`, giving a far out-of-bounds heap write of a partly controlled `int`; the fix\u0027s added bounds checks confirm this is an out-of-bounds write suitable for heap corruption and control-flow hijack.\nA:H - A garbage `stats_idx` can address up to \u00b132 GB from the stats buffer, so dereferencing unmapped or non-canonical memory produces a kernel oops/panic, and the OOB write can corrupt adjacent slab objects and crash the system."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:35:53.971Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/32675d828c8a392e20d5b42375ed112c407e4b62"
        },
        {
          "url": "https://git.kernel.org/stable/c/af9bcf910b1f86244f39e15e701b2dc564b469a6"
        }
      ],
      "title": "gve: Account for stopped queues when reading NIC stats",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-42162",
    "datePublished": "2024-07-30T07:47:04.050Z",
    "dateReserved": "2024-07-29T15:50:41.197Z",
    "dateUpdated": "2026-08-05T11:35:53.971Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/32675d828c8a392e20d5b42375ed112c407e4b62\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/af9bcf910b1f86244f39e15e701b2dc564b469a6\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T04:54:32.609Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-42162\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T16:14:49.244034Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:14.635Z\"}}], \"cna\": {\"title\": \"gve: Account for stopped queues when reading NIC stats\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"2f523dc34ac8c355609e9b847852bf25bbdb30bf\", \"lessThan\": \"32675d828c8a392e20d5b42375ed112c407e4b62\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"2f523dc34ac8c355609e9b847852bf25bbdb30bf\", \"lessThan\": \"af9bcf910b1f86244f39e15e701b2dc564b469a6\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/net/ethernet/google/gve/gve_ethtool.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.10\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.10\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.9.9\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.9.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/net/ethernet/google/gve/gve_ethtool.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/32675d828c8a392e20d5b42375ed112c407e4b62\"}, {\"url\": \"https://git.kernel.org/stable/c/af9bcf910b1f86244f39e15e701b2dc564b469a6\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ngve: Account for stopped queues when reading NIC stats\\n\\nWe now account for the fact that the NIC might send us stats for a\\nsubset of queues. Without this change, gve_get_ethtool_stats might make\\nan invalid access on the priv-\u003estats_report-\u003estats array.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9.9\", \"versionStartIncluding\": \"5.10\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10\", \"versionStartIncluding\": \"5.10\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2025-05-21T09:13:02.476Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-42162\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-05-21T09:13:02.476Z\", \"dateReserved\": \"2024-07-29T15:50:41.197Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-07-30T07:47:04.050Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…