Resource Exhaustion Affecting bpftool package, versions *
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-CENTOS7-BPFTOOL-7763751
- published 21 Aug 2024
- disclosed 17 Aug 2024
Introduced: 17 Aug 2024
CVE-2024-42291 Open this link in a new tabHow to fix?
There is no fixed version for Centos:7
bpftool
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream bpftool
package and not the bpftool
package as distributed by Centos
.
See How to fix?
for Centos:7
relevant fixed versions and status.
In the Linux kernel, the following vulnerability has been resolved:
ice: Add a per-VF limit on number of FDIR filters
While the iavf driver adds a s/w limit (128) on the number of FDIR filters that the VF can request, a malicious VF driver can request more than that and exhaust the resources for other VFs.
Add a similar limit in ice.
References
- https://access.redhat.com/security/cve/CVE-2024-42291
- https://git.kernel.org/stable/c/292081c4e7f575a79017d5cbe1a0ec042783976f
- https://git.kernel.org/stable/c/6ebbe97a488179f5dc85f2f1e0c89b486e99ee97
- https://git.kernel.org/stable/c/8e02cd98a6e24389d476e28436d41e620ed8e559
- https://git.kernel.org/stable/c/d62389073a5b937413e2d1bc1da06ccff5103c0c
- https://git.kernel.org/stable/c/e81b674ead8e2172b2a69e7b45e079239ace4dbc