CVE-2024-46679 is a moderate-severity Linux kernel flaw in ethtool link-settings handling that can cause a kernel panic when a sysfs reader races with a network device being reset or removed. The issue, observed in the qede driver path, permits __ethtool_get_link_ksettings() callers to access device state after it is no longer present, affecting availability only. It has a CVSS v3.1 score of 4.7 and requires local access, low privileges, and high attack complexity.
The defect has existed since Linux 2.6.33 and affects net/core/net-sysfs.c and net/ethtool/ioctl.c. Upstream fixes add a device-presence check for all ethtool callers and are included in stable kernels 5.4.283, 5.10.225, 5.15.166, 6.1.108, 6.6.49, 6.10.8, and 6.11-rc6. Red Hat issued fixes for affected RHEL 8 and 9 streams through errata including RHSA-2024:8107, RHSA-2024:8856, and RHSA-2024:10274; organizations should apply the applicable vendor kernel updates, noting that Red Hat may backport fixes without changing to the listed upstream version.

See real exploitation activity before you spend the cycle.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.