Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's ALX network driver has been addressed by modifying the resume process to properly manage the RTNL lock. Previously, the driver did not hold the RTNL lock during its internal close and reopen procedures while suspending and resuming, which led to an assertion failure. Although this issue was not critical since the driver has its own locking mechanism and does not change the number of queues, the adjustment was necessary to prevent the assertion error from occurring.
The vulnerability could cause an RTNL assertion failure, disrupting the normal operation of the network driver.
The issue can be reproduced by resuming a system with the ALX network driver loaded. The absence of the RTNL lock during the driver's resume process will trigger the assertion failure.
Users can upgrade to the latest version of the Linux kernel where this issue has been fixed. Instructions for downloading the patched version are available on the Linux kernel official website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.