CVE-2024-50209

Description

A flaw was found in the RDMA/bnxt_re component of the Linux kernel. This vulnerability occurs because the driver fails to check the return status of a memory allocation function, __alloc_pbl(). A local attacker with administrative privileges could exploit this flaw, potentially leading to system instability or a denial of service.

Statement

This issue is considered to be a moderate impact flaw, as the exploitation for this will need an ADMIN (or ROOT) privilege (PR:H).

Mitigation

If RDMA functionality provided by the `bnxt_re` kernel module is not required, the module can be prevented from loading to mitigate this vulnerability.
To blacklist the `bnxt_re` module:
1. Create a file `/etc/modprobe.d/blacklist-bnxt_re.conf` with the following content:

   blacklist bnxt_re
install bnxt_re /bin/true
2. Regenerate the initramfs:
   - For RHEL 8/9: `dracut -f -v`
   - For RHEL 7: `dracut -f`
3. Reboot the system for the changes to take effect.
This mitigation will disable any functionality relying on the `bnxt_re` RDMA driver.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.77.87.8
Attack VectorLocalLocalLocal
Attack ComplexityLowLowLow
Privileges RequiredHighLowLow
User InteractionNoneNoneNone
ScopeUnchangedUnchangedUnchanged
ConfidentialityHighHighHigh
Integrity ImpactHighHighHigh
Availability ImpactHighHighHigh

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

cve.org: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Understanding the Weakness (CWE)

Availability,Integrity

Technical Impact: Unexpected State; DoS: Crash, Exit, or Restart

An unexpected return value could place the system in a state that could lead to a crash or other unintended behaviors.

Frequently Asked Questions

Want to get errata notifications? Sign up here.