5.5

CVE-2024-40990

RDMA/mlx5: Add check for srq max_sge attribute

In the Linux kernel, the following vulnerability has been resolved:

RDMA/mlx5: Add check for srq max_sge attribute

max_sge attribute is passed by the user, and is inserted and used
unchecked, so verify that the value doesn't exceed maximum allowed value
before using it.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 3.11 < 5.10.221
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.162
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.96
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.36
Linux ≫ Linux Kernel Version >= 6.7 < 6.9.7
Linux ≫ Linux Kernel Version 6.10 Update rc1
Linux ≫ Linux Kernel Version 6.10 Update rc2
Linux ≫ Linux Kernel Version 6.10 Update rc3
Linux ≫ Linux Kernel Version 6.10 Update rc4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.202
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1e692244bf7dd827dd72edc6c4a3b36ae572f03c
Patch
https://git.kernel.org/stable/c/36ab7ada64caf08f10ee5a114d39964d1f91e81d
Patch
https://git.kernel.org/stable/c/4ab99e3613139f026d2d8ba954819e2876120ab3
Patch
https://git.kernel.org/stable/c/7186b81c1f15e39069b1af172c6a951728ed3511
Patch
https://git.kernel.org/stable/c/999586418600b4b3b93c2a0edd3a4ca71ee759bf
Patch
https://git.kernel.org/stable/c/e0deb0e9c967b61420235f7f17a4450b4b4d6ce2
Patch
https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html