Answer in brief
CVE-2024-46717 records a Unknown severity vulnerability in net/mlx5e: SHAMPO, Fix incorrect page release. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7957837b816f11eecb9146235bb0715478f4c81f <03924d117625ecb10ee3c9b65930bcb2c37ae629 || >=7957837b816f11eecb9146235bb0715478f4c81f <ae9018e3f61ba5cc1f08a6e51d3c0bef0a79f3ab || >=7957837b816f11eecb9146235bb0715478f4c81f <c909ab41df2b09cde919801c7a7b6bb2cc37ea22 || >=7957837b816f11eecb9146235bb0715478f4c81f <70bd03b89f20b9bbe51a7f73c4950565a17a45f7 || a4161e4861132d5b324746a260283e87f2d65daf || >=5.16.6 <5.17 | 03924d117625ecb10ee3c9b65930bcb2c37ae629, ae9018e3f61ba5cc1f08a6e51d3c0bef0a79f3ab, c909ab41df2b09cde919801c7a7b6bb2cc37ea22, 70bd03b89f20b9bbe51a7f73c4950565a17a45f7, 5.17 |
| Linux/Linuxgeneric | 5.17 | Not reported |
Published upstream
Sep 18, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix incorrect page release Under the following conditions: 1) No skb created yet 2) header_size == 0 (no SHAMPO header) 3) header_index + 1 % MLX5E_SHAMPO_WQ_HEADER_PER_PAGE == 0 (this is the last page fragment of a SHAMPO header page) a new skb is formed with a page that is NOT a SHAMPO header page (it is a regular data page). Further down in the same function (mlx5e_handle_rx_cqe_mpwrq_shampo()), a SHAMPO header page from header_index is released. This is wrong and it leads to SHAMPO header pages being released more than once.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-46717 records a Unknown severity vulnerability in net/mlx5e: SHAMPO, Fix incorrect page release. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7957837b816f11eecb9146235bb0715478f4c81f <03924d117625ecb10ee3c9b65930bcb2c37ae629 || >=7957837b816f11eecb9146235bb0715478f4c81f <ae9018e3f61ba5cc1f08a6e51d3c0bef0a79f3ab || >=7957837b816f11eecb9146235bb0715478f4c81f <c909ab41df2b09cde919801c7a7b6bb2cc37ea22 || >=7957837b816f11eecb9146235bb0715478f4c81f <70bd03b89f20b9bbe51a7f73c4950565a17a45f7 || a4161e4861132d5b324746a260283e87f2d65daf || >=5.16.6 <5.17 | 03924d117625ecb10ee3c9b65930bcb2c37ae629, ae9018e3f61ba5cc1f08a6e51d3c0bef0a79f3ab, c909ab41df2b09cde919801c7a7b6bb2cc37ea22, 70bd03b89f20b9bbe51a7f73c4950565a17a45f7, 5.17 |
| Linux/Linuxgeneric | 5.17 | Not reported |
Published upstream
Sep 18, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix incorrect page release Under the following conditions: 1) No skb created yet 2) header_size == 0 (no SHAMPO header) 3) header_index + 1 % MLX5E_SHAMPO_WQ_HEADER_PER_PAGE == 0 (this is the last page fragment of a SHAMPO header page) a new skb is formed with a page that is NOT a SHAMPO header page (it is a regular data page). Further down in the same function (mlx5e_handle_rx_cqe_mpwrq_shampo()), a SHAMPO header page from header_index is released. This is wrong and it leads to SHAMPO header pages being released more than once.
Quoted source text, attributed separately from HOL analysis.