Back

HIGH

bnxt: prevent skb UAF after handing over to PTP worker

Published Apr 28, 2024

Description

When reading the timestamp is required bnxt_tx_int() hands over the ownership of the completed skb to the PTP worker. The skb should not be used afterwards, as the worker may run before the rest of our code and free the skb, leading to a use-after-free.

Since dev_kfree_skb_any() accepts NULL make the loss of ownership more obvious and set skb to NULL.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Apr 28, 2024
Updated Aug 5, 2026
Reserved Feb 25, 2024
CISA Vulnrichment
Updated Jun 7, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Apr 28, 2024