CVE-2024-39507
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash problem in concurrent scenario When link status change, the nic driver need to notify the roce driver to handle this event, but at this time, the roce driver…
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash problem in concurrent scenario When link status change, the nic driver need to notify the roce driver to handle this event, but at this time, the roce driver may uninit, then cause kernel crash. To fix the problem, when link status change, need to check whether the roce registered, and when uninit, need to wait link update finish.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.30% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-908
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/12cda920212a49fa22d9e8b9492ac4ea013310a4Patch
- https://git.kernel.org/stable/c/62b5dfb67bfa8bd0301bf3442004563495f9ee48Patch
- https://git.kernel.org/stable/c/689de7c3bfc7d47e0eacc641c4ce4a0f579aeefaPatch
- https://git.kernel.org/stable/c/6d0007f7b69d684879a0f598a042e40244d3cf63Patch
- https://git.kernel.org/stable/c/b2c5024b771cd1dd8175d5f6949accfadbab7eddPatch
- https://git.kernel.org/stable/c/12cda920212a49fa22d9e8b9492ac4ea013310a4Patch
- https://git.kernel.org/stable/c/62b5dfb67bfa8bd0301bf3442004563495f9ee48Patch
- https://git.kernel.org/stable/c/689de7c3bfc7d47e0eacc641c4ce4a0f579aeefaPatch
- https://git.kernel.org/stable/c/6d0007f7b69d684879a0f598a042e40244d3cf63Patch
- https://git.kernel.org/stable/c/b2c5024b771cd1dd8175d5f6949accfadbab7eddPatch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.