Executive brief
A vulnerability in the Linux kernel's Lantiq Ethernet driver could allow sensitive system memory to be leaked over the network. This occurs because the software fails to clear memory buffers when adding required padding to small network packets, potentially exposing fragments of previous system activity to anyone monitoring the network traffic. This affects devices using Amazon-SE and Danube Ethernet hardware.
Technical details
A memory disclosure vulnerability exists in the lantiq_etop.c Ethernet driver within the Linux kernel. The driver performs software padding for Ethernet MACs (specifically Amazon-SE and Danube) that do not support hardware padding. However, the driver failed to zero the padding buffer before transmission, causing uninitialized kernel memory to be sent over the wire. An attacker on the same network segment could capture these frames to inspect leaked kernel data. The fix replaces manual length adjustment with skb_put_padto(), which ensures the padding bytes are properly zeroed.
Affected products
- Linux Linux Kernel 3.0 to 5.10.227, 5.11 to 5.15.168, 5.16 to 6.1.113, 6.2 to 6.6.55, 6.7 to 6.10.14, 6.11 to 6.11.3
Timeline
- 2024-10-21: advisory: Initial publication of CVE-2024-49997
- 2024-10-10: patched: Fix committed to various stable kernel branches
References
- https://git.kernel.org/stable/c/1097bf16501ed5e35358d848b0a94ad2830b0f65
- https://git.kernel.org/stable/c/185df159843d30fb71f821e7ea4368c2a3bfcd36
- https://git.kernel.org/stable/c/2bf4c101d7c99483b8b15a0c8f881e3f399f7e18
- https://git.kernel.org/stable/c/431b122933b197820d319eb3987a67d04346ce9e
- https://git.kernel.org/stable/c/45c0de18ff2dc9af01236380404bbd6a46502c69
- https://git.kernel.org/stable/c/469856f76f4802c5d7e3d20e343185188de1e2db
- https://git.kernel.org/stable/c/60c068444c20bf9a3e22b65b5f6f3d9edc852931