In the Linux kernel, the following vulnerability has been resolved: enetc: Fix illegal access when reading affinity_hint irq_set_affinity_hit() stores a reference to the cpumask_t parameter in the irq descriptor, and that reference can be accessed later from irq_affinity_hint_proc_show(). Since the cpu_mask parameter passed to irq_set_affinity_hit() has only temporary storage (it's on the stack memory), later accesses to it are illegal. Thus reads from the corresponding procfs affinity_hint file can result in paging request oops. The issue is fixed by the get_cpu_mask() helper, which provides a permanent storage for the cpumask_t parameter.
Update Linux/Linux to 4c4c3052911b577920353a7646e4883d5da40c28; linux/linux_kernel to 6c3f1b741c6c; linux/linux_kernel to 6f329d9da2a5; linux/linux_kernel to 7237a494decf; linux/linux_kernel to 4c4c3052911b if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanenetc: Fix illegal access when reading affinity_hint affects Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic), linux/linux_kernel (generic), linux/linux_kernel (generic), linux/linux_kernel (generic), linux/linux_kernel (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: enetc: Fix illegal access when reading affinity_hint irq_set_affinity_hit() stores a reference to the cpumask_t parameter in the irq descriptor, and that reference can be accessed later from irq_affinity_hint_proc_show(). Since the cpu_mask parameter passed to irq_set_affinity_hit() has only temporary storage (it's on the stack memory), later accesses to it are illegal. Thus reads from the corresponding procfs affinity_hint file can result in paging request oops. The issue is fixed by the get_cpu_mask() helper, which provides a permanent storage for the cpumask_t parameter.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
In the Linux kernel, the following vulnerability has been resolved: enetc: Fix illegal access when reading affinity_hint irq_set_affinity_hit() stores a reference to the cpumask_t parameter in the irq descriptor, and that reference can be accessed later from irq_affinity_hint_proc_show(). Since the cpu_mask parameter passed to irq_set_affinity_hit() has only temporary storage (it's on the stack memory), later accesses to it are illegal. Thus reads from the corresponding procfs affinity_hint file can result in paging request oops. The issue is fixed by the get_cpu_mask() helper, which provides a permanent storage for the cpumask_t parameter.
Update Linux/Linux to 4c4c3052911b577920353a7646e4883d5da40c28; linux/linux_kernel to 6c3f1b741c6c; linux/linux_kernel to 6f329d9da2a5; linux/linux_kernel to 7237a494decf; linux/linux_kernel to 4c4c3052911b if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanenetc: Fix illegal access when reading affinity_hint affects Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic), linux/linux_kernel (generic), linux/linux_kernel (generic), linux/linux_kernel (generic), linux/linux_kernel (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: enetc: Fix illegal access when reading affinity_hint irq_set_affinity_hit() stores a reference to the cpumask_t parameter in the irq descriptor, and that reference can be accessed later from irq_affinity_hint_proc_show(). Since the cpu_mask parameter passed to irq_set_affinity_hit() has only temporary storage (it's on the stack memory), later accesses to it are illegal. Thus reads from the corresponding procfs affinity_hint file can result in paging request oops. The issue is fixed by the get_cpu_mask() helper, which provides a permanent storage for the cpumask_t parameter.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| Linux/Linuxgeneric | >=d4fd0404c1c95b17880f254ebfee3485693fa8ba <4c4c3052911b577920353a7646e4883d5da40c28 || >=d4fd0404c1c95b17880f254ebfee3485693fa8ba <6c3f1b741c6c2914ea120e3a5790d3e900152f7b || >=d4fd0404c1c95b17880f254ebfee3485693fa8ba <6f329d9da2a5ae032fcde800a99b118124ed5270 || >=d4fd0404c1c95b17880f254ebfee3485693fa8ba <7237a494decfa17d0b9d0076e6cee3235719de90 | 4c4c3052911b577920353a7646e4883d5da40c28, 6c3f1b741c6c2914ea120e3a5790d3e900152f7b, 6f329d9da2a5ae032fcde800a99b118124ed5270, 7237a494decfa17d0b9d0076e6cee3235719de90 |
|---|---|---|
| Linux/Linuxgeneric | 5.1 | Not reported |
| linux/linux_kernelgeneric | >=d4fd0404c1c9 <6c3f1b741c6c | 6c3f1b741c6c |
| linux/linux_kernelgeneric | >=d4fd0404c1c9 <6f329d9da2a5 | 6f329d9da2a5 |
| linux/linux_kernelgeneric | >=d4fd0404c1c9 <7237a494decf | 7237a494decf |
| linux/linux_kernelgeneric | 5.1 | Not reported |
| linux/linux_kernelgeneric | >=d4fd0404c1c9 <4c4c3052911b | 4c4c3052911b |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|
| Linux/Linuxgeneric | >=d4fd0404c1c95b17880f254ebfee3485693fa8ba <4c4c3052911b577920353a7646e4883d5da40c28 || >=d4fd0404c1c95b17880f254ebfee3485693fa8ba <6c3f1b741c6c2914ea120e3a5790d3e900152f7b || >=d4fd0404c1c95b17880f254ebfee3485693fa8ba <6f329d9da2a5ae032fcde800a99b118124ed5270 || >=d4fd0404c1c95b17880f254ebfee3485693fa8ba <7237a494decfa17d0b9d0076e6cee3235719de90 | 4c4c3052911b577920353a7646e4883d5da40c28, 6c3f1b741c6c2914ea120e3a5790d3e900152f7b, 6f329d9da2a5ae032fcde800a99b118124ed5270, 7237a494decfa17d0b9d0076e6cee3235719de90 |
|---|---|---|
| Linux/Linuxgeneric | 5.1 | Not reported |
| linux/linux_kernelgeneric | >=d4fd0404c1c9 <6c3f1b741c6c | 6c3f1b741c6c |
| linux/linux_kernelgeneric | >=d4fd0404c1c9 <6f329d9da2a5 | 6f329d9da2a5 |
| linux/linux_kernelgeneric | >=d4fd0404c1c9 <7237a494decf | 7237a494decf |
| linux/linux_kernelgeneric | 5.1 | Not reported |
| linux/linux_kernelgeneric | >=d4fd0404c1c9 <4c4c3052911b | 4c4c3052911b |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard