#VU99176 Resource management error in Linux kernel - CVE-2024-47693


Vulnerability identifier: #VU99176

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-47693

CWE-ID: CWE-399

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the ib_cache_setup_one() function in drivers/infiniband/core/cache.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/1730d47d1865af89efd01cf0469a9a739cbf60f2
https://git.kernel.org/stable/c/45f63f4bb9a7128a6209d766c2fc02b3d42fbf3e
https://git.kernel.org/stable/c/d08754be993f270e3d296d8f5d8e071fe6638651
https://git.kernel.org/stable/c/af633fd9d9fff59e31c804f47ca0c8a784977773
https://git.kernel.org/stable/c/290fe42fe0165205c4451334d8833a9202ae1d52
https://git.kernel.org/stable/c/1403c8b14765eab805377dd3b75e96ace8747aed


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability