Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-40992
HistoryJul 12, 2024 - 12:00 a.m.

CVE-2024-40992

2024-07-1200:00:00
ubuntu.com
ubuntu.com
3
linux kernel
rdma/rxe
vulnerability
iba specification
ud request packet
responder length checking
regression issue
receive buffer
error state
unix

AI Score

7.2

Confidence

Low

In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix responder length checking for UD request packets
According to the IBA specification:
If a UD request packet is detected with an invalid length, the request
shall be an invalid request and it shall be silently dropped by
the responder. The responder then waits for a new request packet.
commit 689c5421bfe0 (“RDMA/rxe: Fix incorrect responder length checking”)
defers responder length check for UD QPs in function copy_data.
But it introduces a regression issue for UD QPs.
When the packet size is too large to fit in the receive buffer.
copy_data will return error code -EINVAL. Then send_data_in
will return RESPST_ERR_MALFORMED_WQE. UD QP will transfer into
ERROR state.

AI Score

7.2

Confidence

Low