CVE-2024-40928 is a null pointer dereference vulnerability in the Linux kernel's ethtool network driver, specifically within the ethtool_get_phy_stats_ethtool() function. This flaw, identified by a Clang static checker, affects Linux kernel versions and has been resolved by ensuring a proper error return when the relevant operations pointer is null. Rated with a CVSS v3.1 score of 5.5 (Medium), this vulnerability has a local attack vector (AV:L) and low attack complexity (AC:L), requiring local user privileges (PR:L). A successful exploit could lead to a denial of service (A:H) due to the null dereference, but does not impact confidentiality or integrity. Currently, there is no known exploit intelligence, including Metasploit modules, Nuclei templates, or ExploitDB entries. The vulnerability also shows minimal community discussion or media coverage, indicating a low level of public attention and no evidence of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2, < 6.6.35CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.9.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:* | ||
6.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.