In the Linux kernel, the following vulnerability has been resolved:
net: dsa: mv88e6xxx: Correct check for empty list
Since commit a3c53be55c95 ("net: dsa: mv88e6xxx: Support multiple MDIO
busses") mv88e6xxx_default_mdio_bus() has checked that the
return value of list_first_entry() is non-NULL.
This appears to be intended to guard against the list chip->mdios being
empty. However, it is not the correct check as the implementation of
list_first_entry is not designed to return NULL for empty lists.
Instead, use list_first_entry_or_null() which does return NULL if the
list is empty.
Flagged by Smatch.
Compile tested only.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 11 Sep 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 16 Aug 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-476 |
MITRE
Status: PUBLISHED
Assigner: Linux
Published: 2024-07-30T07:47:05.608Z
Updated: 2024-09-11T17:34:33.427Z
Reserved: 2024-07-30T07:40:12.250Z
Link: CVE-2024-42224
Vulnrichment
Updated: 2024-08-02T04:54:32.570Z
NVD
Status : Analyzed
Published: 2024-07-30T08:15:07.667
Modified: 2024-08-02T14:24:16.187
Link: CVE-2024-42224
Redhat