kernel CVE-2024-1151
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.19.3
Patched versions
1.19.3
kernel-5.15
(bottlerocket)
< 1.19.3
1.19.3
kernel-6.1
(bottlerocket)
< 1.19.3
1.19.3
A flaw was found in the Linux kernel's Open vSwitch component. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stack depth, pushing too many frames and causing a stack overflow. This can lead to a crash or other issues.