Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A denial-of-service vulnerability has been identified in the Linux kernel's bnxt_en driver, specifically in versions prior to 5.10.156. The issue arises from the driver allocating a large chunk of memory (order-5) on systems with 4K pages to manage concurrent TPA (TCP Segmentation Offload) completions. This excessive allocation can lead to memory allocation failures, as reported by NetworkManager. The vulnerability is particularly relevant for users with P5 chips, where the driver must handle up to 256 concurrent TPA instances.
Excessive memory allocation can cause allocation failures, leading to denial-of-service conditions where the NetworkManager is unable to function properly.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.