GPU VulnDB

Database/Control plane, storage & DevOps

Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (insufficient access control leading

CVE-2020-24503Control plane, storage & DevOpscurated

Impact

Early E810 Linux driver flaw (insufficient access control leading to information disclosure) reachable by an authenticated local user. Present on nodes still running the original E810 driver, which happens when the out-of-tree driver was pinned at deployment and never revisited.

Who can reach it

Authenticated local user on the node.

What to do

Fixed in the Intel out-of-tree ice driver (or the equivalent in-kernel version). Updating the driver requires unloading and reloading the module, which drops every link on that NIC - on a node whose RDMA fabric carries collective traffic, that is a job-killing event, so drain first. If you take it via a distro kernel update instead, it is a reboot. No firmware flash for the driver-side fixes.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.