cbcvebase.
CVE-2024-38556
published 2024-06-19

CVE-2024-38556: In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Add a timeout to acquire the command queue semaphore Prevent forced completion…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.6th percentile
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Add a timeout to acquire the command queue semaphore Prevent forced completion handling on an entry that has not yet been assigned an index, causing an out of bounds access on idx = -22. Instead of waiting indefinitely for the sem, blocking flow now waits for index to be allocated or a sem acquisition timeout before beginning the timer for FW completion. Kernel log example: mlx5_core 0000:06:00.0: wait_func_handle_exec_timeout:1128:(pid 185911): cmd[-22]: CREATE_UCTX(0xa04) No done completion

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 5.10.94 < 5.115.11
linuxlinux>= 5.15.17 < 5.165.16
linuxlinux>= 5.16.3 < 5.175.17
linuxlinux>= 5.4.174 < 5.55.5
linuxlinux>= 8e715cd613a1e872b9d918e912d90b399785761a < 4baae687a20ef2b82fde12de3c04461e6f2521d64baae687a20ef2b82fde12de3c04461e6f2521d6
linuxlinux>= 8e715cd613a1e872b9d918e912d90b399785761a < f9caccdd42e999b74303c9b0643300073ed5d319f9caccdd42e999b74303c9b0643300073ed5d319
linuxlinux>= 8e715cd613a1e872b9d918e912d90b399785761a < 2d0962d05c93de391ce85f6e764df895f47c89182d0962d05c93de391ce85f6e764df895f47c8918
linuxlinux>= 8e715cd613a1e872b9d918e912d90b399785761a < 94024332a129c6e4275569d85c0c1bfb2ae2d71b94024332a129c6e4275569d85c0c1bfb2ae2d71b
linuxlinux>= 8e715cd613a1e872b9d918e912d90b399785761a < 485d65e1357123a697c591a5aeb773994b247ad7485d65e1357123a697c591a5aeb773994b247ad7
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.10.94 < 5.115.11
linuxlinux_kernel>= 5.15.17 < 5.165.16
linuxlinux_kernel5.16.3 – 6.1.93
linuxlinux_kernel>= 5.4.174 < 5.55.5
linuxlinux_kernel6.2 – 6.6.33
linuxlinux_kernel6.7 – 6.8.12

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.