
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability in the Linux kernel's idpf driver has been identified and assigned CVE-2024-35889. The issue occurs in the rare case where a packet type is unknown to the driver, causing idpf_rx_process_skb_fields to return early without calling eth_type_trans to set the skb protocol and network layer handler. This vulnerability affects Linux kernel versions from 6.7 up to (excluding) 6.8.5, as well as 6.9-rc1 and 6.9-rc2 (NVD).
The vulnerability exists in the idpf driver's packet processing functionality. When an unknown packet type is encountered, the driver fails to properly set up the network layer handler by skipping the eth_type_trans call. The issue has been assigned a CVSS v3.1 base score of 5.5 MEDIUM (Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) (NVD).
The primary impact of this vulnerability is a potential kernel panic, particularly when tcpdump is running and an unknown packet type is received. This can lead to system instability and denial of service conditions (Kernel Patch).
The vulnerability requires local access and specific conditions to be exploited, particularly the presence of tcpdump running when an unknown packet type is received. The issue is considered to have low complexity but requires local privileges to exploit (NVD).
The vulnerability has been patched by modifying the idpf driver to call eth_type_trans for every packet, regardless of whether the packet type is unknown. The fix has been implemented in the Linux kernel, and users are advised to upgrade to kernel version 6.8.5 or later (Kernel Patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."