Kernel: stack overflow problem in open vswitch kernel module leading to dos
Vulnerability Description
A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stack depth, pushing too many frames and causing a stack overflow. As a result, this can lead to a crash or other related issues.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1151
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This issue was discovered by Aaron Conole (Red Hat).
References
- https://access.redhat.com/errata/RHSA-2024:4823
- https://access.redhat.com/errata/RHSA-2024:4831
- https://access.redhat.com/errata/RHSA-2024:9315
- https://access.redhat.com/security/cve/CVE-2024-1151
- https://bugzilla.redhat.com/show_bug.cgi?id=2262241
- https://lore.kernel.org/all/20240207132416.1488485-1-aconole@redhat.com/
More from Red Hat
View All →Affected Vendor
Red Hat
View all reports →