{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-44933",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-08-21T05:34:56.664Z",
        "datePublished": "2024-08-26T10:11:24.675Z",
        "dateUpdated": "2026-08-05T11:37:06.259Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:37:06.259Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en : Fix memory out-of-bounds in bnxt_fill_hw_rss_tbl()\n\nA recent commit has modified the code in __bnxt_reserve_rings() to\nset the default RSS indirection table to default only when the number\nof RX rings is changing.  While this works for newer firmware that\nrequires RX ring reservations, it causes the regression on older\nfirmware not requiring RX ring resrvations (BNXT_NEW_RM() returns\nfalse).\n\nWith older firmware, RX ring reservations are not required and so\nhw_resc->resv_rx_rings is not always set to the proper value.  The\ncomparison:\n\nif (old_rx_rings != bp->hw_resc.resv_rx_rings)\n\nin __bnxt_reserve_rings() may be false even when the RX rings are\nchanging.  This will cause __bnxt_reserve_rings() to skip setting\nthe default RSS indirection table to default to match the current\nnumber of RX rings.  This may later cause bnxt_fill_hw_rss_tbl() to\nuse an out-of-range index.\n\nWe already have bnxt_check_rss_tbl_no_rmgr() to handle exactly this\nscenario.  We just need to move it up in bnxt_need_reserve_rings()\nto be called unconditionally when using older firmware.  Without the\nfix, if the TX rings are changing, we'll skip the\nbnxt_check_rss_tbl_no_rmgr() call and __bnxt_reserve_rings() may also\nskip the bnxt_set_dflt_rss_indir_tbl() call for the reason explained\nin the last paragraph.  Without setting the default RSS indirection\ntable to default, it causes the regression:\n\nBUG: KASAN: slab-out-of-bounds in __bnxt_hwrm_vnic_set_rss+0xb79/0xe40\nRead of size 2 at addr ffff8881c5809618 by task ethtool/31525\nCall Trace:\n__bnxt_hwrm_vnic_set_rss+0xb79/0xe40\n bnxt_hwrm_vnic_rss_cfg_p5+0xf7/0x460\n __bnxt_setup_vnic_p5+0x12e/0x270\n __bnxt_open_nic+0x2262/0x2f30\n bnxt_open_nic+0x5d/0xf0\n ethnl_set_channels+0x5d4/0xb30\n ethnl_default_set_doit+0x2f1/0x620"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The only trigger is a local `ethtool -L`/set-channels request delivered over an `AF_NETLINK` genetlink socket or the `SIOCETHTOOL` ioctl; no remote peer data reaches `bnxt_need_reserve_rings()`/`bnxt_fill_hw_rss_tbl_p5()`.\nAC:L - The attacker deterministically creates every precondition by simply reducing the channel count from a higher value (`ethtool -L ethX combined 1`), which changes TX rings and thus takes the early `return true` that skips `bnxt_check_rss_tbl_no_rmgr()`; the stale default table then indexes `bp->rx_ring[]` out of range on the very next `bnxt_open_nic()`. No race, no memory-layout luck, and the attacker also chooses the overread distance by picking the starting and ending ring counts.\nPR:L - Both entry points gate only on `CAP_NET_ADMIN` evaluated against the netns owner's user namespace (`GENL_UNS_ADMIN_PERM`/`ns_capable(net->user_ns, ...)`), not real root; a bnxt VF handed to a container or pod netns is administered by an otherwise unprivileged principal who holds that capability locally.\nUI:N - The attacker issues the channel-count change from its own process and the out-of-bounds access happens synchronously in that syscall; no victim action or cooperation is involved.\nS:U - The overread and the resulting misprogramming occur entirely within the kernel's own security authority on the same PCI function; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - `rxr = &bp->rx_ring[j]` with `j` up to the previous ring count reads `fw_ring_id` at attacker-selected offsets tens of kilobytes beyond a `kcalloc()`ed array — far more than a strictly bounded few-byte overread — and the harvested kernel heap words are programmed into the hardware RSS table, whose steering effect is observable through per-ring `ethtool -S` counters, yielding an oracle on adjacent kernel memory.\nI:L - There is no out-of-bounds write, but the values scavenged from unrelated kernel memory are committed to the NIC via `HWRM_VNIC_RSS_CFG`, corrupting the device's RX steering configuration with ring IDs neither the kernel nor the administrator intended.\nA:H - The read runs ~75 KB past a small slab object, producing a KASAN slab-out-of-bounds report (panic under `panic_on_warn`/KASAN panic) and a plausible page-fault oops on unmapped memory; even when it survives, the bogus ring IDs make `HWRM_VNIC_RSS_CFG` fail and `__bnxt_open_nic()` abort, leaving the interface down, and the sequence is cheap and repeatable."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
                    ],
                    "versions": [
                        {
                            "version": "bc57f879a420d19bb5ecdb480f858371554f2258",
                            "lessThan": "abd573e9ad2ba64eaa6418a5f4eec819de28f205",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "98ba1d931f611e8f8f519c0405fa0a1a76554bfa",
                            "lessThan": "da03f5d1b2c319a2b74fe76edeadcd8fa5f44376",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/net/ethernet/broadcom/bnxt/bnxt.c"
                    ],
                    "versions": [
                        {
                            "version": "6.10.4",
                            "lessThan": "6.10.5",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.10.4",
                                    "versionEndExcluding": "6.10.5"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/abd573e9ad2ba64eaa6418a5f4eec819de28f205"
                },
                {
                    "url": "https://git.kernel.org/stable/c/da03f5d1b2c319a2b74fe76edeadcd8fa5f44376"
                }
            ],
            "title": "bnxt_en : Fix memory out-of-bounds in bnxt_fill_hw_rss_tbl()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2024-44933",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2024-09-10T15:27:54.693041Z"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-09-12T17:32:56.097Z"
                }
            }
        ]
    }
}