SB20241230297 - Input validation error in Linux kernel octeontx2 nic driver
Published: December 30, 2024 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2024-56707)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the otx2_dmacflt_do_add() and otx2_dmacflt_update() functions in drivers/net/ethernet/marvell/octeontx2/nic/otx2_dmac_flt.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1611b1ea7cf8d07dff091a45389b10401bb6d5b3
- https://git.kernel.org/stable/c/20e06a5137a1174214bae3a29ce623e69455ee0f
- https://git.kernel.org/stable/c/3ccbc7a518868eff1d5a198b9e454e182b651e00
- https://git.kernel.org/stable/c/f5b942e6c54b13246ee49d42dcfb71b7f29e3c64
- https://git.kernel.org/stable/c/fc595472fbad96533ccbb7b9ebb82b743ec26829
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.2