CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-23981

CVSS 9.3v4.0pub. 2024-08-14upd. 2024-09-06

Wrap-around error in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

🤖 AI Analysis
How it works

The wrap-around error (CWE-128) consists of improper wrapping of numeric values during arithmetic calculations (CWE-682), which leads to errors in memory management or control logic in the Linux kernel mode driver. An attacker with local system access can exploit this impropriety to perform operations leading to privilege escalation in the kernel context of the operating system. The attack does not require user interaction or special system conditions.

Impact

An authenticated local user can obtain elevated privileges in the system, potentially reaching kernel privilege level, which enables complete takeover of the operating system and infrastructure resources.

Mitigation & patch

The driver should be updated to version 28.3 or newer. Detailed information about available patches is available in the Intel security bulletin: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html

Who is affected

Linux kernel mode driver for Intel Ethernet Network controllers and adapters (Intel Ethernet 800 series) in versions before 28.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Intel Ethernet 800 Series Controllers Driver

    APP
    Intel
    < 28.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-23497CRITICAL9.3PL ✓same product

Out-of-bounds write w sterowniku Linux dla Intel Ethernet 800 Series — privilege escalation

CVE-2024-24986CRITICAL9.3PL ✓same product

Nieprawidłowa kontrola dostępu w sterowniku Intel Ethernet 800 Series — privilege escalation

CVE-2024-23499HIGH7.0same product

Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Ad...

CVE-2021-45046CRITICAL9.0⚠ KEVPL ✓same vendor

Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup

CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same vendor

Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup