In the Linux kernel, the following vulnerability has been resolved:
firmware_loader: Block path traversal
Most firmware names are hardcoded strings, or are constructed from fairly
constrained format strings where the dynamic parts are just some hex
numbers or such.
However, there are a couple codepaths in the kernel where firmware file
names contain string components that are passed through from a device or
semi-privileged userspace; the ones I could find (not counting interfaces
that require root privileges) are:
- lpfc_sli4_request_firmware_update() seems to construct the firmware
filename from "ModelName", a string that was previously parsed out of
some descriptor ("Vital Product Data") in lpfc_fill_vpd()
- nfp_net_fw_find() seems to construct a firmware filename from a model
name coming from nfp_hwinfo_lookup(pf->hwinfo, "nffw.partno"), which I
think parses some descriptor that was read from the device.
(But this case likely isn't exploitable because the format string looks
like "netronome/nic_%s", and there shouldn't be any *folders* starting
with "netronome/nic_". The previous case was different because there,
the "%s" is *at the start* of the format string.)
- module_flash_fw_schedule() is reachable from the
ETHTOOL_MSG_MODULE_FW_FLASH_ACT netlink command, which is marked as
GENL_UNS_ADMIN_PERM (meaning CAP_NET_ADMIN inside a user namespace is
enough to pass the privilege check), and takes a userspace-provided
firmware name.
(But I think to reach this case, you need to have CAP_NET_ADMIN over a
network namespace that a special kind of ethernet device is mapped into,
so I think this is not a viable attack path in practice.)
Fix it by rejecting any firmware names containing ".." path components.
For what it's worth, I went looking and haven't found any USB device
drivers that use the firmware loader dangerously.
Security readout for executives and security teams
Plain-English summary
A Linux kernel firmware-loading flaw could let a locally positioned, low-privileged actor or device-controlled value escape the intended firmware path. Successful abuse could affect confidentiality, integrity, and availability. Practical exploitation depends on reaching specific firmware-loading paths and suitable hardware or namespace conditions.
Executive priority
Treat as a high-priority kernel maintenance issue, but not an evidence-backed emergency. Accelerate remediation on multi-user, hardware-management, virtualization, and network-administration hosts. Normal expedited patch cycles may be appropriate for tightly controlled systems without relevant devices or delegated privileges.
Technical view
The firmware loader insufficiently rejected firmware names containing ".." path components. Some names can incorporate device descriptors or semi-privileged userspace input, creating path-traversal risk. The kernel fix rejects such components. The record assigns CVSS 3.1 score 7.8: local access, low complexity, low privileges, no user interaction, and high impact.
Likely exposure
Systems running affected Linux kernels are potentially exposed, especially where relevant firmware-loading drivers, controllable devices, or delegated CAP_NET_ADMIN capabilities exist. The supplied affected-version data spans several kernel series but is not sufficiently precise for package-level decisions; distribution backports must be checked separately.
Exploitation context
The supplied sources do not establish active exploitation, and the CVE is not listed as KEV. The researcher considered some identified paths unlikely or impractical, while the lpfc device-derived filename path appeared more concerning. Exploitation remains environment-dependent and requires local or device-influenced access.
Researcher notes
The strongest described concern is lpfc firmware naming derived from device Vital Product Data. The nfp path appears constrained by a fixed directory prefix, while the netlink module-flash path requires CAP_NET_ADMIN and specialized device mapping. These are source-author assessments, not proof that exploitation is impossible. No USB driver path was identified.
Mitigation direction
Install a vendor-supported kernel update containing the path-traversal fix.
Confirm distribution advisories and package changelogs because vendors may backport fixes without changing major versions.
Prioritize systems exposing relevant firmware-loading drivers or semi-privileged network administration capabilities.
If patching is delayed, restrict untrusted device access and unnecessary delegated CAP_NET_ADMIN privileges.
Validation and detection
Inventory deployed kernel versions and distribution package revisions.
Verify each kernel package explicitly includes the CVE-2024-47742 fix or cited backport.
Identify systems using lpfc, nfp, or module firmware-flashing functionality.
Review local privilege delegation, user namespaces, and device exposure affecting reachable firmware-loading paths.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
description · low confidence lookup
File access behavior lookup
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.