kernel: Improper validation in bnx2x network card driver can allow for denial of service attacks via crafted packet
Published Feb 9, 2018
7.7
HIGHCVSS 3.1
EPSS 4.02%
Description
Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..
Affected products
No data.
Configuration 1
- ≥ 2.6.12 · < 4.4.181
- ≥ 4.5.0 · < 4.9.159
- ≥ 4.10 · < 4.14.102
- ≥ 4.15 · < 4.16
Configuration 2
- 12.04
- 14.04
- 16.04
- 17.10
Configuration 3
- 7.0
- 7.0
- 7.0
- 7.0
Configuration 4
- 8.0
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-957.el7
Fixed · RHSA-2018:3083
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.el7a
Fixed · RHSA-2018:2948
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-957.rt56.910.el7
Fixed · RHSA-2018:3096
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise MRG 2
realtime-kernel
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-957.el7 | Fixed | RHSA-2018:3083 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.el7a | Fixed | RHSA-2018:2948 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-957.rt56.910.el7 | Fixed | RHSA-2018:3096 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6, as supported configurations are not affected. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7, its real-time kernel, Red Hat Enterprise MRG 2, Red Hat Enterprise Linux 7 for ARM 64 and Red Hat Enterprise Linux 7 for Power 9 LE. Future Linux kernel updates for the respective releases may address this issue.
References (19)
- http://lists.openwall.net/netdev/2018/01/16/40 mailing-listx_refsource_MLISTThird Party Advisory
- http://lists.openwall.net/netdev/2018/01/18/96 mailing-listx_refsource_MLISTThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2948 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3083 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3096 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-1000026 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1541846 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2019/05/msg00002.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000026
- https://patchwork.ozlabs.org/patch/859410/ x_refsource_MISCThird Party Advisory
- https://usn.ubuntu.com/3617-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3617-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3617-3/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3619-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3619-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3620-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3620-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3632-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-1000026
| Link | Providers | Tags |
|---|---|---|
| http://lists.openwall.net/netdev/2018/01/16/40 | mailing-listx_refsource_MLISTThird Party Advisory | |
| http://lists.openwall.net/netdev/2018/01/18/96 | mailing-listx_refsource_MLISTThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2018:2948 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2018:3083 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2018:3096 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-1000026 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1541846 | Issue Tracking | |
| https://lists.debian.org/debian-lts-announce/2019/05/msg00002.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000026 | ||
| https://patchwork.ozlabs.org/patch/859410/ | x_refsource_MISCThird Party Advisory | |
| https://usn.ubuntu.com/3617-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://usn.ubuntu.com/3617-2/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://usn.ubuntu.com/3617-3/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://usn.ubuntu.com/3619-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://usn.ubuntu.com/3619-2/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://usn.ubuntu.com/3620-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://usn.ubuntu.com/3620-2/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://usn.ubuntu.com/3632-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-1000026 |
Change history (0)
No recorded changes yet.