Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ice: Add a per-VF limit on number of FDIR filters While the iavf driver adds a s/w limit (128) on the number of FDIR filters that the VF can request, a malicious VF driver can request more than that and exhaust the resources for other VFs. Add a similar limit in ice.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.13, < 5.15.172 |
References
- https://git.kernel.org/stable/c/292081c4e7f575a79017d5cbe1a0ec042783976fPatch
- https://git.kernel.org/stable/c/6ebbe97a488179f5dc85f2f1e0c89b486e99ee97Patch
- https://git.kernel.org/stable/c/8e02cd98a6e24389d476e28436d41e620ed8e559Patch
- https://git.kernel.org/stable/c/d62389073a5b937413e2d1bc1da06ccff5103c0cPatch
- https://git.kernel.org/stable/c/e81b674ead8e2172b2a69e7b45e079239ace4dbcPatch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
FAQ
What is CVE-2024-42291?
CVE-2024-42291 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: ice: Add a per-VF limit on number of FDIR filters While the iavf driver adds a s/w limit (128) on the number of FDIR filters that ...
How severe is CVE-2024-42291?
CVE-2024-42291 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-42291?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.