cbcvebase.
CVE-2024-26820
published 2024-04-17

CVE-2024-26820: In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Register VF in netvsc_probe if NET_DEVICE_REGISTER missed If hv_netvsc driver is…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.8th percentile
In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Register VF in netvsc_probe if NET_DEVICE_REGISTER missed If hv_netvsc driver is unloaded and reloaded, the NET_DEVICE_REGISTER handler cannot perform VF register successfully as the register call is received before netvsc_probe is finished. This is because we register register_netdevice_notifier() very early( even before vmbus_driver_register()). To fix this, we try to register each such matching VF( if it is visible as a netdevice) at the end of netvsc_probe.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 028aa21f9e92536038cabb834c15d08f5c894382 < bcb7164258d0a9a8aa2e73ddccc2d78f67d2519dbcb7164258d0a9a8aa2e73ddccc2d78f67d2519d
linuxlinux>= 4.19.301 < 4.19.3104.19.310
linuxlinux>= 5.10.203 < 5.10.2135.10.213
linuxlinux>= 5.15.141 < 5.15.1525.15.152
linuxlinux>= 5.4.263 < 5.4.2725.4.272
linuxlinux>= 5dd83db613be8e5c5d30efed7f42780e9eb18380 < 309ef7de5d840e17607e7d65cbf297c0564433ef309ef7de5d840e17607e7d65cbf297c0564433ef
linuxlinux>= 6.1.65 < 6.1.796.1.79
linuxlinux>= 6.6.4 < 6.6.186.6.18
linuxlinux>= 7350c460f7f48a8653a15c5c90fc9070aaa29535 < a71302c8638939c45e4ba5a99ea438185fd3f418a71302c8638939c45e4ba5a99ea438185fd3f418
linuxlinux>= 85520856466ed6bc3b1ccb013cddac70ceb437db < 4d29a58d96a78728cb01ee29ed70dc4bd642f1354d29a58d96a78728cb01ee29ed70dc4bd642f135
linuxlinux>= 85520856466ed6bc3b1ccb013cddac70ceb437db < 9cae43da9867412f8bd09aee5c8a8dc5e8dc3dc29cae43da9867412f8bd09aee5c8a8dc5e8dc3dc2
linuxlinux>= 97683466e24c801ee4e865ce90ac7e355db2da59 < b6d46f306b3964d05055ddaa96b58cd8bd3a472cb6d46f306b3964d05055ddaa96b58cd8bd3a472c
linuxlinux>= 997d895fa495fb3421983923219bba93f1a793ee < c7441c77c91e47f653104be8353b44a3366a5366c7441c77c91e47f653104be8353b44a3366a5366
linuxlinux>= ff6c130e48a79c826cbc2427bd8b34a7592460cc < 5b10a88f64c0315cfdef45de0aaaa4eef57de0b75b10a88f64c0315cfdef45de0aaaa4eef57de0b7
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 4.19.301 < 4.19.3104.19.310

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.