cbcvebase.
CVE-2024-38544
published 2024-06-19

CVE-2024-38544: In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt In rxe_comp_queue_pkt() an incoming response…

PriorityP426medium6.3CVSS 3.1
AVLACHPRLUINSUCNIHAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt In rxe_comp_queue_pkt() an incoming response packet skb is enqueued to the resp_pkts queue and then a decision is made whether to run the completer task inline or schedule it. Finally the skb is dereferenced to bump a 'hw' performance counter. This is wrong because if the completer task is already running in a separate thread it may have already processed the skb and freed it which can cause a seg fault. This has been observed infrequently in testing at high scale. This patch fixes this by changing the order of enqueuing the packet until after the counter is accessed.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0 < c91fb72a2ca6480d8d77262eef52dc5b178463a3c91fb72a2ca6480d8d77262eef52dc5b178463a3
linuxlinux>= 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0 < de5a059e36657442b5637cc16df5163e435b9cb4de5a059e36657442b5637cc16df5163e435b9cb4
linuxlinux>= 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0 < e0e14dd35d4242340c7346aac60c7ff8fbf87ffce0e14dd35d4242340c7346aac60c7ff8fbf87ffc
linuxlinux>= 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0 < faa8d0ecf6c9c7c2ace3ca3e552180ada6f75e19faa8d0ecf6c9c7c2ace3ca3e552180ada6f75e19
linuxlinux>= 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0 < 21b4c6d4d89030fd4657a8e7c8110fd94104979421b4c6d4d89030fd4657a8e7c8110fd941049794
linuxlinux>= 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0 < bbad88f111a1829f366c189aa48e7e58e57553fcbbad88f111a1829f366c189aa48e7e58e57553fc
linuxlinux>= 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0 < 30df4bef8b8e183333e9b6e9d4509d552c7da6eb30df4bef8b8e183333e9b6e9d4509d552c7da6eb
linuxlinux>= 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0 < 2b23b6097303ed0ba5f4bc036a1c07b6027af5c62b23b6097303ed0ba5f4bc036a1c07b6027af5c6
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 4.12 < 5.4.2855.4.285
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.936.1.93
linuxlinux_kernel>= 5.5 < 5.10.2275.10.227
linuxlinux_kernel>= 6.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.8.126.8.12
linuxlinux_kernel>= 6.9 < 6.9.36.9.3

CVSS provenance

nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.