CVE-2024-40923 is a vulnerability in the Linux kernel's vmxnet3 driver, specifically affecting virtual machines using VMware's network adapter. It occurs when memory allocation for the receive data ring fails, leading to the hypervisor referencing an improperly configured data ring during packet reception. This can result in a kernel crash, causing a denial of service. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in high availability impact. There is no known impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.3.1, < 6.6.35CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.9.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.3:-:*:*:*:*:*:* | ||
6.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:* | ||
6.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.