CVE-2018-1000026

Description

Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..

Risk Information

Base Score
7.7
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.865

Associated Vulnerability

VulnerabilityOS Platform
Kernel-uek update (ELSA-2021-9534) kernel-uek-4.1.12-124.57.1.el7uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2021-9534) kernel-uek-debug-4.1.12-124.57.1.el7uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2021-9534) kernel-uek-debug-devel-4.1.12-124.57.1.el7uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2021-9534) kernel-uek-devel-4.1.12-124.57.1.el7uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2021-9534) kernel-uek-doc-4.1.12-124.57.1.el7uek.noarch.rpmLinux
Kernel-uek-firmware update (ELSA-2021-9534) kernel-uek-firmware-4.1.12-124.57.1.el7uek.noarch.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234