CVE-2024-42291

MEDIUM

Linux Kernel 5.13-6.10.2 - Unauthenticated Resource Exhaustion via FDIR Filter Requests

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ice: Add a per-VF limit on number of FDIR filters While the iavf driver adds a s/w limit (128) on the number of FDIR filters that the VF can request, a malicious VF driver can request more than that and exhaust the resources for other VFs. Add a similar limit in ice.

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (17)
linux/Kernel 5.13.0 - 5.15.172linux
linux/Kernel 5.16.0 - 6.1.103linux
linux/Kernel 6.2.0 - 6.6.44linux
linux/Kernel 6.7.0 - 6.10.3linux
Linux/Linux < 5.13
Linux/Linux 1f7ea1cd6a3748427512ccc9582e18cd9efea966 - 292081c4e7f575a79017d5cbe1a0ec042783976f
Linux/Linux 1f7ea1cd6a3748427512ccc9582e18cd9efea966 - 6ebbe97a488179f5dc85f2f1e0c89b486e99ee97
Linux/Linux 1f7ea1cd6a3748427512ccc9582e18cd9efea966 - 8e02cd98a6e24389d476e28436d41e620ed8e559
Linux/Linux 1f7ea1cd6a3748427512ccc9582e18cd9efea966 - d62389073a5b937413e2d1bc1da06ccff5103c0c
Linux/Linux 1f7ea1cd6a3748427512ccc9582e18cd9efea966 - e81b674ead8e2172b2a69e7b45e079239ace4dbc
... and 7 more
Published Aug 17, 2024
Tracked Since Feb 18, 2026