Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2024-50188

Description

In the Linux kernel, the following vulnerability has been resolved:net: phy: dp83869: fix memory corruption when enabling fiberWhen configuring the fiber port, the DP83869 PHY driver incorrectlycalls linkmode_set_bit() with a bit mask (1 << 10) rather than a bitnumber (10). This corrupts some other memory location -- in case ofarm64 the priv pointer in the same structure.Since the advertising flags are updated from supported at the end of thefunction the incorrect line isn't needed at all and can be removed.

POC

Reference

No PoCs from references.

Github

- https://github.com/w4zu/Debian_security