Back

HIGH

net: mscc: ocelot: fix use-after-free in ocelot_vlan_del()

Published Jul 16, 2024

Description

ocelot_vlan_member_del() will free the struct ocelot_bridge_vlan, so if this is the same as the port's pvid_vlan which we access afterwards, what we're accessing is freed memory.

Fix the bug by determining whether to clear ocelot_port->pvid_vlan prior to calling ocelot_vlan_member_del().

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux is not vulnerable to this CVE, as it does not affect the versions or configurations of the Linux kernel used in its distributions.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jul 16, 2024
Updated Aug 5, 2026
Reserved Jun 20, 2024
CISA Vulnrichment
Updated Sep 10, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Jul 16, 2024
ENISA EUVD
Assigner Linux
Published Jul 16, 2024
Updated Aug 5, 2026
Exploited since n/a
EUVD-2022-53658