Answer in brief
CVE-2024-44988 records a Unknown severity vulnerability in net: dsa: mv88e6xxx: Fix out-of-bound access. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-44988 records a Unknown severity vulnerability in net: dsa: mv88e6xxx: Fix out-of-bound access. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=27a2fa0098171199022affa76bdf15d77585457f <4a88fca95c8df3746b71e31f44a02d35f06f9864 || >=75c05a74e745ae7d663b04d75777af80ada2233c <d39f5be62f098fe367d672b4dd4bc4b2b80e08e7 || >=75c05a74e745ae7d663b04d75777af80ada2233c <050e7274ab2150cd212b2372595720e7b83a15bd || >=75c05a74e745ae7d663b04d75777af80ada2233c <a10d0337115a6d223a1563d853d4455f05d0b2e3 || >=75c05a74e745ae7d663b04d75777af80ada2233c <18b2e833daf049223ab3c2efdf8cdee08854c484 || >=75c05a74e745ae7d663b04d75777af80ada2233c <f7d8c2fabd39250cf2333fbf8eef67e837f90a5d || >=75c05a74e745ae7d663b04d75777af80ada2233c <f87ce03c652dba199aef15ac18ade3991db5477e || >=75c05a74e745ae7d663b04d75777af80ada2233c <528876d867a23b5198022baf2e388052ca67c952 || 1657d2814e83d3e338d6d60c5829d15d86645bc0 || >=4.19.21 <4.19.323 || >=4.20.8 <4.21 | 4a88fca95c8df3746b71e31f44a02d35f06f9864, d39f5be62f098fe367d672b4dd4bc4b2b80e08e7, 050e7274ab2150cd212b2372595720e7b83a15bd, a10d0337115a6d223a1563d853d4455f05d0b2e3, 18b2e833daf049223ab3c2efdf8cdee08854c484, f7d8c2fabd39250cf2333fbf8eef67e837f90a5d, f87ce03c652dba199aef15ac18ade3991db5477e, 528876d867a23b5198022baf2e388052ca67c952, 4.19.323, 4.21 |
| Linux/Linuxgeneric | 5.0 | Not reported |
Published upstream
Sep 4, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Fix out-of-bound access If an ATU violation was caused by a CPU Load operation, the SPID could be larger than DSA_MAX_PORTS (the size of mv88e6xxx_chip.ports[] array).
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=27a2fa0098171199022affa76bdf15d77585457f <4a88fca95c8df3746b71e31f44a02d35f06f9864 || >=75c05a74e745ae7d663b04d75777af80ada2233c <d39f5be62f098fe367d672b4dd4bc4b2b80e08e7 || >=75c05a74e745ae7d663b04d75777af80ada2233c <050e7274ab2150cd212b2372595720e7b83a15bd || >=75c05a74e745ae7d663b04d75777af80ada2233c <a10d0337115a6d223a1563d853d4455f05d0b2e3 || >=75c05a74e745ae7d663b04d75777af80ada2233c <18b2e833daf049223ab3c2efdf8cdee08854c484 || >=75c05a74e745ae7d663b04d75777af80ada2233c <f7d8c2fabd39250cf2333fbf8eef67e837f90a5d || >=75c05a74e745ae7d663b04d75777af80ada2233c <f87ce03c652dba199aef15ac18ade3991db5477e || >=75c05a74e745ae7d663b04d75777af80ada2233c <528876d867a23b5198022baf2e388052ca67c952 || 1657d2814e83d3e338d6d60c5829d15d86645bc0 || >=4.19.21 <4.19.323 || >=4.20.8 <4.21 | 4a88fca95c8df3746b71e31f44a02d35f06f9864, d39f5be62f098fe367d672b4dd4bc4b2b80e08e7, 050e7274ab2150cd212b2372595720e7b83a15bd, a10d0337115a6d223a1563d853d4455f05d0b2e3, 18b2e833daf049223ab3c2efdf8cdee08854c484, f7d8c2fabd39250cf2333fbf8eef67e837f90a5d, f87ce03c652dba199aef15ac18ade3991db5477e, 528876d867a23b5198022baf2e388052ca67c952, 4.19.323, 4.21 |
| Linux/Linuxgeneric | 5.0 | Not reported |
Published upstream
Sep 4, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Fix out-of-bound access If an ATU violation was caused by a CPU Load operation, the SPID could be larger than DSA_MAX_PORTS (the size of mv88e6xxx_chip.ports[] array).
Quoted source text, attributed separately from HOL analysis.