VDB
DEBIAN-CVE-2024-40990
DEBIAN-CVE-2024-40990
PUBLISHED
CVSS 5.5 MEDIUM
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Add check for srq max_sge attribute max_sge attribute is passed by the user, and is inserted and used unchecked, so verify that the value doesn't exceed maximum allowed value before using it.
Risk Scores
CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | linux-6.1 | 6.1.106-3, 6.1.112-1, 6.1.106-3 |
| Debian:12 | linux | 6.1.64-1, 6.1.66-1, 6.1.67-1 |
| Debian:11 | linux | 5.10.179-2, 5.10.179-3, 5.10.179-4 |
| Debian:14 | linux | 0, 0 |
| Debian:13 | linux | 0, 0 |
Timeline
- Jul 12, 2024 CVE Published
- Apr 28, 2026 CVE Updated