CLOS Network Vulnerability in Linux Kernel Affects Nexthop Functionality
CVE-2024-14040
Currently unrated
What is CVE-2024-14040?
A vulnerability exists within the Linux kernel that affects the nexthop configuration in CLOS (Clos) networks. With the high fan-out of nodes and multiple link failures, the default 8-bit ECMP weight might not suffice, necessitating an increase to 16-bits for proper weight representation. The modification facilitates configuring weights like 1000:999, which previously exceeded the limitation. The type conversion process has been designed with caution to ensure backward compatibility and prevent numerical errors. Existing userspace applications remain unaffected while allowing new configurations, promoting better network resilience.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux 6.12