CVE-2020-24504: Medium severity intel ethernet network adapter e810 firmware vulnerability
An uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux may allow an authenticated user to potentially cause a denial of service via local access.
Other sources
Description: Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable denial of service via local access.
References:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00462.html
— Red Hat
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-24504?
CVE-2020-24504 is classified as a medium-severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2020-24504?
To resolve CVE-2020-24504, update the Intel Ethernet E810 Adapter drivers to versions 0:4.18.0-348.rt7.130.el8 or 0:4.18.0-348.el8 or later.
What impact does CVE-2020-24504 have on my system?
CVE-2020-24504 allows an authenticated user to cause uncontrolled resource consumption, leading to a potential denial of service.
Which systems are affected by CVE-2020-24504?
CVE-2020-24504 affects certain versions of Intel Ethernet E810 Adapter drivers for Linux prior to 0:4.18.0-348.rt7.130.el8 and 0:4.18.0-348.el8.
Is CVE-2020-24504 exploitable remotely?
No, CVE-2020-24504 requires local access to be exploited.