cbcvebase.
CVE-2024-40990
published 2024-07-12

CVE-2024-40990: In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Add check for srq max_sge attribute max_sge attribute is passed by the user, and…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.2th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Add check for srq max_sge attribute max_sge attribute is passed by the user, and is inserted and used unchecked, so verify that the value doesn't exceed maximum allowed value before using it.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < 7186b81c1f15e39069b1af172c6a951728ed35117186b81c1f15e39069b1af172c6a951728ed3511
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < 1e692244bf7dd827dd72edc6c4a3b36ae572f03c1e692244bf7dd827dd72edc6c4a3b36ae572f03c
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < 999586418600b4b3b93c2a0edd3a4ca71ee759bf999586418600b4b3b93c2a0edd3a4ca71ee759bf
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < e0deb0e9c967b61420235f7f17a4450b4b4d6ce2e0deb0e9c967b61420235f7f17a4450b4b4d6ce2
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < 4ab99e3613139f026d2d8ba954819e2876120ab34ab99e3613139f026d2d8ba954819e2876120ab3
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < 36ab7ada64caf08f10ee5a114d39964d1f91e81d36ab7ada64caf08f10ee5a114d39964d1f91e81d
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 3.11 < 5.10.2215.10.221
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.966.1.96
linuxlinux_kernel>= 6.2 < 6.6.366.6.36
linuxlinux_kernel>= 6.7 < 6.9.76.9.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.