Vulnary
← back to the feed
Critical· 9.8official fix available

CVE-2024-57936

A critical flaw in the Linux kernel's RDMA/bnxt_re driver incorrectly reports the maximum number of scatter-gather elements (SGEs) for work requests can lead to traffic, allowing requests that exceed the hardware's capability and causing system crashes or traffic failures. The issue has been resolved in the kernel by fixing the max SGE limit to match what the hardware supports. Users should apply the kernel patch or upgrade to a kernel version that includes this fix.

publishedJan 21, 2025
last modifiedAug 4, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
9th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 3, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Linux kernel users, particularly those using RDMA/bnxt_re devices.

02

Real-world impact

Potential denial of service through system crashes or network traffic disruption.

03

Why this severity

CVSS 3.1 base score 9.8 (Critical) due to network‑adjacent, low‑complexity attack with no privileges or user interaction required, leading to full compromise of confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 01Obtain the Linux kernel patch that fixes the RDMA/bnxt_re max SGEs issue (as referenced in the NVD description).
  2. 02Apply the patch to the affected kernel or upgrade to a kernel version that includes this fix.
  3. 03Reboot the system to ensure the updated kernel is loaded.

NVD-referenced vendor advisory (the NVD description states the vulnerability has been resolved in the Linux kernel).

05

Timeline

  1. Jan 21, 2025 · Jan 21, 2025
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Aug 4, 2026 · 2d ago
    Advisory updated
    The NVD record was last revised.
  3. Aug 4, 2026 · 1d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →