CVE-2024-40999: net: ena: Add validation for completion descriptors consistency
In the Linux kernel, the following vulnerability has been resolved:
net: ena: Add validation for completion descriptors consistency
Validate that first flag is set only for the first descriptor in multi-buffer packets. In case of an invalid descriptor, a reset will occur. A new reset reason for RX data corruption has been added.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40999?
CVE-2024-40999 has a moderate severity level as it can cause a reset due to invalid descriptor handling.
How do I fix CVE-2024-40999?
To fix CVE-2024-40999, update to a patched version of the linux package, specifically versions 6.12.12-1 or 6.12.13-1.
What systems are affected by CVE-2024-40999?
CVE-2024-40999 affects specific versions of the Linux kernel in Debian, primarily versions up to 5.10.226-1 and 6.1.128-1.
What is the nature of the issue in CVE-2024-40999?
CVE-2024-40999 consists of a validation flaw in completion descriptors that can lead to resets in multi-buffer packets.
Is there a workaround for CVE-2024-40999?
There are no documented workarounds for CVE-2024-40999, so applying the recommended updates is crucial.