CVE-2024-40990

MEDIUM

Linux Kernel 3.11-6.9.7 RDMA/mlx5 SRQ max_sge Unchecked User Input

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Add check for srq max_sge attribute max_sge attribute is passed by the user, and is inserted and used unchecked, so verify that the value doesn't exceed maximum allowed value before using it.

Scores

CVSS v3 5.5
EPSS 0.0027
EPSS Percentile 18.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (21)
linux/Kernel 3.11.0 - 5.10.221linux
linux/Kernel 5.11.0 - 5.15.162linux
linux/Kernel 5.16.0 - 6.1.96linux
linux/Kernel 6.2.0 - 6.6.36linux
linux/Kernel 6.7.0 - 6.9.7linux
Linux/Linux < 3.11
Linux/Linux 3.11
Linux/Linux 5.10.221 - 5.10.*
Linux/Linux 5.15.162 - 5.15.*
Linux/Linux 6.1.96 - 6.1.*
... and 11 more
Published Jul 12, 2024
Tracked Since Feb 18, 2026