cbcvebase.
CVE-2024-36004
published 2024-05-20

CVE-2024-36004: In the Linux kernel, the following vulnerability has been resolved: i40e: Do not use WQ_MEM_RECLAIM flag for workqueue Issue reported by customer during SRIOV…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.0th percentile
In the Linux kernel, the following vulnerability has been resolved: i40e: Do not use WQ_MEM_RECLAIM flag for workqueue Issue reported by customer during SRIOV testing, call trace: When both i40e and the i40iw driver are loaded, a warning in check_flush_dependency is being triggered. This seems to be because of the i40e driver workqueue is allocated with the WQ_MEM_RECLAIM flag, and the i40iw one is not. Similar error was encountered on ice too and it was fixed by removing the flag. Do the same for i40e too. [Feb 9 09:08] ------------[ cut here ]------------ [ +0.000004] workqueue: WQ_MEM_RECLAIM i40e:i40e_service_task [i40e] is flushing !WQ_MEM_RECLAIM infiniband:0x0 [ +0.000060] WARNING: CPU: 0 PID: 937 at kernel/workqueue.c:2966 check_flush_dependency+0x10b/0x120 [ +0.000007] Modules linked in: snd_seq_dummy snd_hrtimer snd_seq snd_timer snd_seq_device snd soundcore nls_utf8 cifs cifs_arc4 nls_ucs2_utils rdma_cm iw_cm ib_cm cifs_md4 dns_resolver netfs qrtr rfkill sunrpc vfat fat intel_rapl_msr intel_rapl_common irdma intel_uncore_frequency intel_uncore_frequency_common ice ipmi_ssif isst_if_common skx_edac nfit libnvdimm x86_pkg_temp_thermal intel_powerclamp gnss coretemp ib_uverbs rapl intel_cstate ib_core iTCO_wdt iTCO_vendor_support acpi_ipmi mei_me ipmi_si intel_uncore ioatdma i2c_i801 joydev pcspkr mei ipmi_devintf lpc_ich intel_pch_thermal i2c_smbus ipmi_msghandler acpi_power_meter acpi_pad xfs libcrc32c ast sd_mod drm_shmem_helper t10_pi drm_kms_helper sg ixgbe drm i40e ahci crct10dif_pclmul libahci crc32_pclmul igb crc32c_intel libata ghash_clmulni_intel i2c_algo_bit mdio dca wmi dm_mirror dm_region_hash dm_log dm_mod fuse [ +0.000050] CPU: 0 PID: 937 Comm: kworker/0:3 Kdump: loaded Not tainted 6.8.0-rc2-Feb-net_dev-Qiueue-00279-gbd43c5687e05 #1 [ +0.000003] Hardware name: Intel Corporation S2600BPB/S2600BPB, BIOS SE5C620.86B.02.01.0013.121520200651 12/15/2020 [ +0.000001] Workqueue: i40e i40e_service_task [i40e] [ +0.000024] RIP: 0010:check_flush_depe

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= 4d5957cbdecdbb77d24c1465caadd801c07afa4a < 09b54d29f05129b092f7c793a70b689ffb3c7b2c09b54d29f05129b092f7c793a70b689ffb3c7b2c
linuxlinux>= 4d5957cbdecdbb77d24c1465caadd801c07afa4a < 546d0fe9d76e8229a67369f9cb61e961d99038bd546d0fe9d76e8229a67369f9cb61e961d99038bd
linuxlinux>= 4d5957cbdecdbb77d24c1465caadd801c07afa4a < fbbb2404340dd6178e281bd427c271f7d5ec1d22fbbb2404340dd6178e281bd427c271f7d5ec1d22
linuxlinux>= 4d5957cbdecdbb77d24c1465caadd801c07afa4a < ff7431f898dd00892a545b7d0ce7adf5b926944fff7431f898dd00892a545b7d0ce7adf5b926944f
linuxlinux>= 4d5957cbdecdbb77d24c1465caadd801c07afa4a < 152ed360cf2d273f88fc99a518b7eb868aae2939152ed360cf2d273f88fc99a518b7eb868aae2939
linuxlinux>= 4d5957cbdecdbb77d24c1465caadd801c07afa4a < 8d6105f637883c8c09825e962308c06e977de4f08d6105f637883c8c09825e962308c06e977de4f0
linuxlinux>= 4d5957cbdecdbb77d24c1465caadd801c07afa4a < 1594dac8b1ed78f9e75c263327e198a2e5e25b0e1594dac8b1ed78f9e75c263327e198a2e5e25b0e
linuxlinux>= 4d5957cbdecdbb77d24c1465caadd801c07afa4a < 2cc7d150550cc981aceedf008f5459193282425c2cc7d150550cc981aceedf008f5459193282425c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 0 < 4.15.0-232.2444.15.0-232.244
linuxlinux_kernel>= 4.14 < 4.19.3134.19.313
linuxlinux_kernel>= 4.20 < 5.4.2755.4.275
linuxlinux_kernel>= 5.11 < 5.15.1585.15.158
linuxlinux_kernel>= 5.16 < 6.1.906.1.90
linuxlinux_kernel>= 5.5 < 5.10.2165.10.216

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.