Описание
In the Linux kernel, the following vulnerability has been resolved:
i40e: add max boundary check for VF filters
There is no check for max filters that VF can request. Add it.
A flaw was found in the Linux kernel's i40e network driver. A local attacker with low privileges can exploit a missing maximum boundary check for Virtual Function (VF) filters. By requesting an unbounded number of filters, the attacker can cause resource exhaustion, leading to a denial of service (DoS). This issue may also impact the confidentiality and integrity of data due to the system's compromised state.
Меры по смягчению последствий
Prevent the i40e kernel module from loading to mitigate this vulnerability. Create a file /etc/modprobe.d/i40e-blacklist.conf with the following content:
Then, regenerate the initramfs and reboot the system for the changes to take effect. This action will disable the i40e network driver, potentially impacting network functionality if i40e-based network adapters are in use. A system reboot is required for the changes to be fully applied.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | ||
| Red Hat Enterprise Linux 6 | kernel | Not affected | ||
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | ||
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | ||
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | ||
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | ||
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | ||
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
In the Linux kernel, the following vulnerability has been resolved: i40e: add max boundary check for VF filters There is no check for max filters that VF can request. Add it.
In the Linux kernel, the following vulnerability has been resolved: i40e: add max boundary check for VF filters There is no check for max filters that VF can request. Add it.
In the Linux kernel, the following vulnerability has been resolved: i ...
In the Linux kernel, the following vulnerability has been resolved: i40e: add max boundary check for VF filters There is no check for max filters that VF can request. Add it.
5.3 Medium
CVSS3