cbcvebase.
CVE-2024-36021
published 2024-05-30

CVE-2024-36021: In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when devlink reload during pf initialization The devlink reload…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when devlink reload during pf initialization The devlink reload process will access the hardware resources, but the register operation is done before the hardware is initialized. So, processing the devlink reload during initialization may lead to kernel crash. This patch fixes this by taking devl_lock during initialization.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= b741269b275953786832805df329851299ab4de7 < 50b69054f455dcdb34bd6b22764c7579b270eef350b69054f455dcdb34bd6b22764c7579b270eef3
linuxlinux>= b741269b275953786832805df329851299ab4de7 < 1b550dae55901c2cc9075d6a7155a71b4f516e861b550dae55901c2cc9075d6a7155a71b4f516e86
linuxlinux>= b741269b275953786832805df329851299ab4de7 < 7ca0f73e5e2da3c129935b97f3a0877cce8ebdf57ca0f73e5e2da3c129935b97f3a0877cce8ebdf5
linuxlinux>= b741269b275953786832805df329851299ab4de7 < 93305b77ffcb042f1538ecc383505e87d95aa05a93305b77ffcb042f1538ecc383505e87d95aa05a
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 5.15 < 6.1.856.1.85
linuxlinux_kernel>= 6.2 < 6.6.266.6.26
linuxlinux_kernel>= 6.7 < 6.8.56.8.5
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.8MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.