LiveActive security incident?Get immediate response
CVE Record

CVE-2024-47742: firmware_loader: Block path traversal

In the Linux kernel, the following vulnerability has been resolved: firmware_loader: Block path traversal Most firmware names are hardcoded strings, or are constructed from fairly constrained format strings where the dynamic parts are just some hex numbers or such. However, there are a couple codepaths in the kernel where firmware file names contain string components that are passed through from a device or semi-privileged userspace; the ones I could find (not counting interfaces that require root privileges) are: - lpfc_sli4_request_firmware_update() seems to construct the firmware filename from "ModelName", a string that was previously parsed out of some descriptor ("Vital Product Data") in lpfc_fill_vpd() - nfp_net_fw_find() seems to construct a firmware filename from a model name coming from nfp_hwinfo_lookup(pf->hwinfo, "nffw.partno"), which I think parses some descriptor that was read from the device. (But this case likely isn't exploitable because the format string looks like "netronome/nic_%s", and there shouldn't be any *folders* starting with "netronome/nic_". The previous case was different because there, the "%s" is *at the start* of the format string.) - module_flash_fw_schedule() is reachable from the ETHTOOL_MSG_MODULE_FW_FLASH_ACT netlink command, which is marked as GENL_UNS_ADMIN_PERM (meaning CAP_NET_ADMIN inside a user namespace is enough to pass the privilege check), and takes a userspace-provided firmware name. (But I think to reach this case, you need to have CAP_NET_ADMIN over a network namespace that a special kind of ethernet device is mapped into, so I think this is not a viable attack path in practice.) Fix it by rejecting any firmware names containing ".." path components. For what it's worth, I went looking and haven't found any USB device drivers that use the firmware loader dangerously.

HighCVSS 7.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A Linux kernel firmware-loading flaw could let a locally positioned, low-privileged actor or device-controlled value escape the intended firmware path. Successful abuse could affect confidentiality, integrity, and availability. Practical exploitation depends on reaching specific firmware-loading paths and suitable hardware or namespace conditions.

Executive priority

Treat as a high-priority kernel maintenance issue, but not an evidence-backed emergency. Accelerate remediation on multi-user, hardware-management, virtualization, and network-administration hosts. Normal expedited patch cycles may be appropriate for tightly controlled systems without relevant devices or delegated privileges.

Technical view

The firmware loader insufficiently rejected firmware names containing ".." path components. Some names can incorporate device descriptors or semi-privileged userspace input, creating path-traversal risk. The kernel fix rejects such components. The record assigns CVSS 3.1 score 7.8: local access, low complexity, low privileges, no user interaction, and high impact.

Likely exposure

Systems running affected Linux kernels are potentially exposed, especially where relevant firmware-loading drivers, controllable devices, or delegated CAP_NET_ADMIN capabilities exist. The supplied affected-version data spans several kernel series but is not sufficiently precise for package-level decisions; distribution backports must be checked separately.

Exploitation context

The supplied sources do not establish active exploitation, and the CVE is not listed as KEV. The researcher considered some identified paths unlikely or impractical, while the lpfc device-derived filename path appeared more concerning. Exploitation remains environment-dependent and requires local or device-influenced access.

Researcher notes

The strongest described concern is lpfc firmware naming derived from device Vital Product Data. The nfp path appears constrained by a fixed directory prefix, while the netlink module-flash path requires CAP_NET_ADMIN and specialized device mapping. These are source-author assessments, not proof that exploitation is impossible. No USB driver path was identified.

Mitigation direction

  • Install a vendor-supported kernel update containing the path-traversal fix.
  • Confirm distribution advisories and package changelogs because vendors may backport fixes without changing major versions.
  • Prioritize systems exposing relevant firmware-loading drivers or semi-privileged network administration capabilities.
  • If patching is delayed, restrict untrusted device access and unnecessary delegated CAP_NET_ADMIN privileges.

Validation and detection

  • Inventory deployed kernel versions and distribution package revisions.
  • Verify each kernel package explicitly includes the CVE-2024-47742 fix or cited backport.
  • Identify systems using lpfc, nfp, or module firmware-flashing functionality.
  • Review local privilege delegation, user namespaces, and device exposure affecting reachable firmware-loading paths.
Prepared
Confidence
high
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

File access behavior lookup

The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2024-47742 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
2ADP providers
12Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.8CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H1.85.9Linux

Vulnerability scoring details

Base CVSS 3.1 score

7.8High
CVSS 3.1 vector shape for CVE-2024-47742Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxabb139e75c2cdbb955e840d6331cb5863e409d0e, abb139e75c2cdbb955e840d6331cb5863e409d0e, abb139e75c2cdbb955e840d6331cb5863e409d0e, abb139e75c2cdbb955e840d6331cb5863e409d0e, abb139e75c2cdbb955e840d6331cb5863e409d0e, abb139e75c2cdbb955e840d6331cb5863e409d0e, abb139e75c2cdbb955e840d6331cb5863e409d0e, abb139e75c2cdbb955e840d6331cb5863e409d0e, abb139e75c2cdbb955e840d6331cb5863e409d0eunaffected
LinuxLinux3.7, 0, 4.19.323, 5.4.285, 5.10.227, 5.15.168, 6.1.113, 6.6.54, 6.10.13, 6.11.2, 6.12affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.