CVE-2024-40940: net/mlx5: Fix tainted pointer delete is case of flow rules creation fail
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix tainted pointer delete is case of flow rules creation fail
In case of flow rule creation fail in mlx5lagcreateportseltable(), instead of previously created rules, the tainted pointer is deleted deveral times. Fix this bug by using correct flow rules pointers.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40940?
The severity of CVE-2024-40940 is classified as moderate.
How do I fix CVE-2024-40940?
To fix CVE-2024-40940, upgrade the Linux kernel to version 6.1.95, 6.6.35, 6.9.6, or 6.10 for Red Hat users, or apply the relevant updates for Debian systems.
What versions of the Linux kernel are affected by CVE-2024-40940?
CVE-2024-40940 affects various versions of the Linux kernel prior to the specified remedial versions, including certain releases under Red Hat and Debian.
Is there a patch available for CVE-2024-40940?
Yes, a patch for CVE-2024-40940 has been provided in the updated versions of the Linux kernel listed in the remediation section.
Where can I find updates for CVE-2024-40940?
Updates for CVE-2024-40940 can typically be found through your Linux distribution's package management system.