cbcvebase.
CVE-2024-38589
published 2024-06-19

CVE-2024-38589: In the Linux kernel, the following vulnerability has been resolved: netrom: fix possible dead-lock in nr_rt_ioctl() syzbot loves netrom, and found a possible…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.4th percentile
In the Linux kernel, the following vulnerability has been resolved: netrom: fix possible dead-lock in nr_rt_ioctl() syzbot loves netrom, and found a possible deadlock in nr_rt_ioctl [1] Make sure we always acquire nr_node_list_lock before nr_node_lock(nr_node) [1] WARNING: possible circular locking dependency detected 6.9.0-rc7-syzkaller-02147-g654de42f3fc6 #0 Not tainted syz-executor350/5129 is trying to acquire lock: ffff8880186e2070 (&nr_node->node_lock){+...}-{2:2}, at: spin_lock_bh include/linux/spinlock.h:356 [inline] ffff8880186e2070 (&nr_node->node_lock){+...}-{2:2}, at: nr_node_lock include/net/netrom.h:152 [inline] ffff8880186e2070 (&nr_node->node_lock){+...}-{2:2}, at: nr_dec_obs net/netrom/nr_route.c:464 [inline] ffff8880186e2070 (&nr_node->node_lock){+...}-{2:2}, at: nr_rt_ioctl+0x1bb/0x1090 net/netrom/nr_route.c:697 but task is already holding lock: ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: spin_lock_bh include/linux/spinlock.h:356 [inline] ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: nr_dec_obs net/netrom/nr_route.c:462 [inline] ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: nr_rt_ioctl+0x10a/0x1090 net/netrom/nr_route.c:697 which lock already depends on the new lock. the existing dependency chain (in reverse order) is: -> #1 (nr_node_list_lock){+...}-{2:2}: lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5754 __raw_spin_lock_bh include/linux/spinlock_api_smp.h:126 [inline] _raw_spin_lock_bh+0x35/0x50 kernel/locking/spinlock.c:178 spin_lock_bh include/linux/spinlock.h:356 [inline] nr_remove_node net/netrom/nr_route.c:299 [inline] nr_del_node+0x4b4/0x820 net/netrom/nr_route.c:355 nr_rt_ioctl+0xa95/0x1090 net/netrom/nr_route.c:683 sock_do_ioctl+0x158/0x460 net/socket.c:1222 sock_ioctl+0x629/0x8e0 net/socket.c:1341 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:904 [inline] __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:890 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf5/0x240 arch/x86/entry/c

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b9d663fbf74290cb68fbc66ae4367bd56837ad1db9d663fbf74290cb68fbc66ae4367bd56837ad1d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1fbfb483c1a290dce3f41f52d45cc46dd88b76911fbfb483c1a290dce3f41f52d45cc46dd88b7691
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b117e5b4f27c2c9076561b6be450a9619f0b79deb117e5b4f27c2c9076561b6be450a9619f0b79de
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 421c50fa81836775bf0fd6ce0e57a6eb27af24d5421c50fa81836775bf0fd6ce0e57a6eb27af24d5
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3db2fc45d1d2a6457f06ebdfd45b9820e5b5c2b73db2fc45d1d2a6457f06ebdfd45b9820e5b5c2b7
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f28bdc2ee5d9300cc77bd3d97b5b3cdd14960fd8f28bdc2ee5d9300cc77bd3d97b5b3cdd14960fd8
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5fb7e2a4335fc67d6952ad2a6613c46e0b05f7c55fb7e2a4335fc67d6952ad2a6613c46e0b05f7c5
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5bc50a705cfac8f64ce51c95611c3dd0554ef9c35bc50a705cfac8f64ce51c95611c3dd0554ef9c3
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e03e7f20ebf7e1611d40d1fdc1bde900fd3335f6e03e7f20ebf7e1611d40d1fdc1bde900fd3335f6
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 2.6.12 < 4.19.3164.19.316
linuxlinux_kernel>= 4.20 < 5.4.2785.4.278
linuxlinux_kernel>= 5.11 < 5.15.1615.15.161
linuxlinux_kernel>= 5.16 < 6.1.936.1.93
linuxlinux_kernel>= 5.5 < 5.10.2195.10.219
linuxlinux_kernel>= 6.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.8.126.8.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.