CVE-2024-42291
MEDIUMLinux Kernel 5.13-6.10.2 - Unauthenticated Resource Exhaustion via FDIR Filter Requests
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ice: Add a per-VF limit on number of FDIR filters While the iavf driver adds a s/w limit (128) on the number of FDIR filters that the VF can request, a malicious VF driver can request more than that and exhaust the resources for other VFs. Add a similar limit in ice.
References (6)
Core 6
Core References
Scores
CVSS v3
5.5
EPSS
0.0023
EPSS Percentile
13.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (17)
linux/Kernel
5.13.0 - 5.15.172linux
linux/Kernel
5.16.0 - 6.1.103linux
linux/Kernel
6.2.0 - 6.6.44linux
linux/Kernel
6.7.0 - 6.10.3linux
Linux/Linux
< 5.13
Linux/Linux
1f7ea1cd6a3748427512ccc9582e18cd9efea966 - 292081c4e7f575a79017d5cbe1a0ec042783976f
Linux/Linux
1f7ea1cd6a3748427512ccc9582e18cd9efea966 - 6ebbe97a488179f5dc85f2f1e0c89b486e99ee97
Linux/Linux
1f7ea1cd6a3748427512ccc9582e18cd9efea966 - 8e02cd98a6e24389d476e28436d41e620ed8e559
Linux/Linux
1f7ea1cd6a3748427512ccc9582e18cd9efea966 - d62389073a5b937413e2d1bc1da06ccff5103c0c
Linux/Linux
1f7ea1cd6a3748427512ccc9582e18cd9efea966 - e81b674ead8e2172b2a69e7b45e079239ace4dbc
... and 7 more
Published
Aug 17, 2024
Tracked Since
Feb 18, 2026