Wind River Support Network

HomeDefectsLIN1023-7070
Fixed

LIN1023-7070 : Security Advisory - linux - CVE-2024-40940

Created: Jul 13, 2024    Updated: Jul 17, 2024
Resolved Date: Jul 14, 2024
Found In Version: 10.23.30.1
Fix Version: 10.23.30.12
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5: Fix tainted pointer delete is case of flow rules creation fail

In case of flow rule creation fail in mlx5_lag_create_port_sel_table(),
instead of previously created rules, the tainted pointer is deleted
deveral times.
Fix this bug by using correct flow rules pointers.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

CREATE(Triage):(User=admin) CVE-2024-40940 (https://nvd.nist.gov/vuln/detail/CVE-2024-40940)

CVEs


Live chat
Online