Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A denial-of-service vulnerability has been identified in the Linux kernel's Fibre Channel transport component. This issue arises from the Link-Integrity and Peer-Congestion FPIN walkers, which improperly handle the pname_count field, leading to an infinite loop. The vulnerability can be exploited by an adjacent Fibre Channel fabric actor that delivers an FPIN ELS frame to a vulnerable Linux initiator, such as those using the lpfc or qla2xxx drivers. The attacker must be able to inject fabric traffic, potentially through a compromised switch or fabric controller, or as a same-zone N_Port on a fabric that allows source spoofing.
Exploitation of this vulnerability causes a non-return in the generic Fibre Channel transport, effectively creating an infinite loop that can disrupt normal operations.
To reproduce this vulnerability, an adjacent Fibre Channel fabric actor must deliver an FPIN ELS frame to a Linux initiator using the lpfc or qla2xxx driver. This can be done by injecting fabric traffic, for example, through a compromised switch or fabric controller, or as a same-zone N_Port on a fabric that permits source spoofing.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for upgrading can be found in the official Linux kernel documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.