Answer in brief
CVE-2024-42282 records a Unknown severity vulnerability in net: mediatek: Fix potential NULL pointer dereference in dummy net_device handling. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d5d57501f543f48df8b76a4af59def9a894b396f <81e82340170ae82f8cc28e76c13a0069c0d47cb4 || >=b209bd6d0bffb8991aba568e2d9a892c86a1a43c <af6bd5c9901b13a26eaf4d57d97a813297791596 || >=b209bd6d0bffb8991aba568e2d9a892c86a1a43c <16f3a28cf5f876a7f3550d8f4c870a7b41bcfaef | 81e82340170ae82f8cc28e76c13a0069c0d47cb4, af6bd5c9901b13a26eaf4d57d97a813297791596, 16f3a28cf5f876a7f3550d8f4c870a7b41bcfaef |
| Linux/Linuxgeneric | 6.10 | Not reported |
Published upstream
Aug 17, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 3, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 3, 2026
In the Linux kernel, the following vulnerability has been resolved: net: mediatek: Fix potential NULL pointer dereference in dummy net_device handling Move the freeing of the dummy net_device from mtk_free_dev() to mtk_remove(). Previously, if alloc_netdev_dummy() failed in mtk_probe(), eth->dummy_dev would be NULL. The error path would then call mtk_free_dev(), which in turn called free_netdev() assuming dummy_dev was allocated (but it was not), potentially causing a NULL pointer dereference. By moving free_netdev() to mtk_remove(), we ensure it's only called when mtk_probe() has succeeded and dummy_dev is fully allocated. This addresses a potential NULL pointer dereference detected by Smatch[1].
Quoted source text, attributed separately from HOL analysis.