CVE-2024-46833·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: net: hns3: void array out of bound when loop tnl_num When query reg inf of SSU, it loops tnl_num times. However, tnl_num comes from hardware and the length of array is a fixed value. To void array out of bound, make sure the loop time is not greater than the length of array
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.10.10
- Published
- 2024-09-27
Affected versions
Until: 6.10.10
Fixed in: 6.10.10
How to fix this CVE
Update your Linux kernel to version 6.10.10 or later to resolve this memory safety issue in the HNS3 network driver. This vulnerability allows an out-of-bounds array access when the hardware reports a tunnel count that exceeds the driver's allocated buffer size. Kernel updates should be applied promptly followed by a system reboot to activate the patched version.
sudo dnf update kernel kernel-devel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Run 'uname -r' to check your current kernel version and confirm it is earlier than 6.10.10
- Check if the HNS3 network driver is loaded: 'lsmod | grep hns3' — if present, your system uses the affected component
- Monitor kernel logs for memory access errors: 'sudo dmesg | grep -i "out of bounds\|array\|hns3"' to detect exploitation attempts
- After patching, verify the new kernel is active with 'uname -r' and confirm it shows version 6.10.10 or newer
FAQ
What is CVE-2024-46833?
This vulnerability exists in the Linux kernel's HNS3 network driver where hardware-provided tunnel counts are not validated against the driver's fixed-size buffer, potentially causing an out-of-bounds memory access that could lead to privilege escalation or denial of service.
Is CVE-2024-46833 being actively exploited?
No, this vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and no public exploits are currently available, though it remains a high-severity local privilege escalation risk.
What versions of Kernel are affected by CVE-2024-46833?
All Linux kernel versions up to and including 6.10.9 are affected; the fix is available in kernel 6.10.10 and later.
How do I check if my server is vulnerable to CVE-2024-46833?
Run 'uname -r' and compare your kernel version to 6.10.10. If your version is 6.10.9 or earlier and 'lsmod | grep hns3' shows the driver is loaded, your system is vulnerable.
Does Defensia detect CVE-2024-46833?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2024-46833 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-46833. Free for 1 server.
Get started free