cbcvebase.
CVE-2024-39507
published 2024-07-12

CVE-2024-39507: In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash problem in concurrent scenario When link status change, the nic…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.30%
22.0th percentile
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash problem in concurrent scenario When link status change, the nic driver need to notify the roce driver to handle this event, but at this time, the roce driver may uninit, then cause kernel crash. To fix the problem, when link status change, need to check whether the roce registered, and when uninit, need to wait link update finish.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab < 62b5dfb67bfa8bd0301bf3442004563495f9ee4862b5dfb67bfa8bd0301bf3442004563495f9ee48
linuxlinux>= 45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab < 6d0007f7b69d684879a0f598a042e40244d3cf636d0007f7b69d684879a0f598a042e40244d3cf63
linuxlinux>= 45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab < 689de7c3bfc7d47e0eacc641c4ce4a0f579aeefa689de7c3bfc7d47e0eacc641c4ce4a0f579aeefa
linuxlinux>= 45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab < b2c5024b771cd1dd8175d5f6949accfadbab7eddb2c5024b771cd1dd8175d5f6949accfadbab7edd
linuxlinux>= 45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab < 12cda920212a49fa22d9e8b9492ac4ea013310a412cda920212a49fa22d9e8b9492ac4ea013310a4
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 5.1 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.956.1.95
linuxlinux_kernel>= 6.2 < 6.6.356.6.35
linuxlinux_kernel>= 6.7 < 6.9.66.9.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.