GPU VulnDB

Database/Control plane, storage & DevOps

Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (improper input validation) reachable

CVE-2020-24502Control plane, storage & DevOpscurated

Impact

Early E810 Linux driver flaw (improper input validation) reachable by an authenticated local user. Present on nodes still running the original E810 driver, which happens when the out-of-tree driver was pinned at deployment and never revisited.

Who can reach it

Authenticated local user on the node.

What to do

Fixed in the Intel out-of-tree ice driver (or the equivalent in-kernel version). Updating the driver requires unloading and reloading the module, which drops every link on that NIC - on a node whose RDMA fabric carries collective traffic, that is a job-killing event, so drain first. If you take it via a distro kernel update instead, it is a reboot. No firmware flash for the driver-side fixes.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.