CVE-2020-24502: Input Validation
Description: Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 and before version 1.4.29.0 for Windows, may allow an authenticated user to potentially enable a denial of service via local access.
References:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00462.html
Other sources
Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux may allow an authenticated user to potentially enable a denial of service via local access.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-24502?
CVE-2020-24502 is a vulnerability that affects certain Intel Ethernet E810 Adapter drivers for Linux and Windows, allowing an authenticated user to potentially enable a denial of service via local access.
How severe is CVE-2020-24502?
CVE-2020-24502 has a severity rating of 5.5, which is considered medium.
What software is affected by CVE-2020-24502?
The affected software includes Intel Ethernet E810 Adapter drivers for Linux versions before 1.0.4 and Windows versions before 1.4.29.0, as well as specific versions of the Red Hat kernel.
How can an authenticated user exploit CVE-2020-24502?
An authenticated user can potentially exploit CVE-2020-24502 by using local access to enable a denial of service.
Where can I find more information about CVE-2020-24502?
More information about CVE-2020-24502 can be found at the following references: [CVE-2020-24502](https://www.cve.org/CVERecord?id=CVE-2020-24502), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-24502), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1930379), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2021:4140).