PT-2019-4036 · Intel · I40E Driver

Ryan Hall

·

Published

2019-05-04

·

Updated

2021-05-03

·

CVE-2019-0146

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions i40e driver for Intel(R) Ethernet 700 Series Controllers versions prior to 2.8.43
Description The issue is related to a resource leak in the i40e driver, which may allow an authenticated user to potentially enable a denial of service via local access. This could be exploited to cause a disruption in service.
Recommendations For versions prior to 2.8.43, update to version 2.8.43 or later to resolve the issue. As a temporary workaround, consider restricting local access to minimize the risk of exploitation.

Fix

Resource Exhaustion

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04597
CVE-2019-0146

Affected Products

I40E Driver