CVE-2024-42142

MEDIUM EPSS 13.1%
Published Jul 30, 20241y ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Jul 30, 2024 1y ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: E-switch, Create ingress ACL when needed Currently, ingress acl is used for three features. It is created only when vport metadata match and prio tag are enabled. But active-backup lag mode also uses it. It is independent of vport metadata match and prio tag. And vport metadata match can be disabled using the following devlink command: # devlink dev param set pci/0000:08:00.0 name esw_port_metadata \ value false cmode runtime If ingress acl is not created, will hit panic when creating drop rule for active-backup lag mode. If always create it, there will be about 5% performance degradation. Fix it by creating ingress acl when needed. If esw_port_metadata is true, ingress acl exists, then create drop rule using existing ingress acl. If esw_port_metadata is false, create ingress acl and then create drop rule.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
13.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 9

VendorProductVersionRange
linuxlinux_kernel*≥5.18  –  <6.1.98
linuxlinux_kernel*≥6.2  –  <6.6.39
linuxlinux_kernel*≥6.7  –  <6.9.9
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any
linuxlinux_kernel6.10any

References 5

  • git.kernel.org https://git.kernel.org/stable/c/3e3551f8702978cd2221d2614ca6d6727e785324
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/83bc1a129f7fd0d7d05036ceb7ee69102624e320
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b20c2fb45470d0c7a603613c9cfa5d45720e17f2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bc3ff8d3c05044de57865ebbb78cca8f7da3e595
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/3e3551f8702978cd2221d2614ca6d6727e785324
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/83bc1a129f7fd0d7d05036ceb7ee69102624e320
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b20c2fb45470d0c7a603613c9cfa5d45720e17f2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bc3ff8d3c05044de57865ebbb78cca8f7da3e595
    Patch