SB20240819152 - Input validation error in Linux kernel intel ice driver
Published: August 19, 2024 Updated: May 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2024-42291)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the ice_vc_fdir_reset_cnt_all(), ice_vc_add_fdir_fltr_post(), ice_vc_del_fdir_fltr_post() and ice_vc_add_fdir_fltr() functions in drivers/net/ethernet/intel/ice/ice_virtchnl_fdir.c, within the ice_parse_rx_flow_user_data() function in drivers/net/ethernet/intel/ice/ice_ethtool_fdir.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/8e02cd98a6e24389d476e28436d41e620ed8e559
- https://git.kernel.org/stable/c/d62389073a5b937413e2d1bc1da06ccff5103c0c
- https://git.kernel.org/stable/c/292081c4e7f575a79017d5cbe1a0ec042783976f
- https://git.kernel.org/stable/c/6ebbe97a488179f5dc85f2f1e0c89b486e99ee97
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.172
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.103
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.10.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.11
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.44