Wind River Support Network

HomeDefectsLIN1024-2739
Fixed

LIN1024-2739 : Security Advisory - linux - CVE-2024-40940

Created: Jul 13, 2024    Updated: Aug 28, 2024
Resolved Date: Jul 14, 2024
Found In Version: 10.24.33.1
Fix Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5: Fix tainted pointer delete is case of flow rules creation fail

In case of flow rule creation fail in mlx5_lag_create_port_sel_table(),
instead of previously created rules, the tainted pointer is deleted
deveral times.
Fix this bug by using correct flow rules pointers.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

CREATE(Triage):(User=admin) CVE-2024-40940 (https://nvd.nist.gov/vuln/detail/CVE-2024-40940)

CVEs


Live chat
Online