Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix max SGEs for the Work Request Gen P7 supports up to 13 SGEs for now. WQE software structure can hold only 6 now. Since the max send sge is reported as 13, the stack can give requests up to 13 SGEs. This is causing traffic failures and system crashes. Use the define for max SGE supported for variable size. This will work for both static and variable WQEs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.12, < 6.12.9 |
References
- https://git.kernel.org/stable/c/3de1b50f055dc2ca7072a526cdda21f691c22dd9Patch
- https://git.kernel.org/stable/c/79d330fbdffd8cee06d8bdf38d82cb62d8363a27Patch
- https://git.kernel.org/stable/c/9a479088e0c8f6140b8c7752b563bc8c6c6dcc8cPatch
FAQ
What is CVE-2024-57936?
CVE-2024-57936 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix max SGEs for the Work Request Gen P7 supports up to 13 SGEs for now. WQE software structure can hold only 6 now....
How severe is CVE-2024-57936?
CVE-2024-57936 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-57936?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.