cbcvebase.
CVE-2024-40968
published 2024-07-12

CVE-2024-40968: In the Linux kernel, the following vulnerability has been resolved: MIPS: Octeon: Add PCIe link status check The standard PCIe configuration read-write…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.30%
22.1th percentile
In the Linux kernel, the following vulnerability has been resolved: MIPS: Octeon: Add PCIe link status check The standard PCIe configuration read-write interface is used to access the configuration space of the peripheral PCIe devices of the mips processor after the PCIe link surprise down, it can generate kernel panic caused by "Data bus error". So it is necessary to add PCIe link status check for system protection. When the PCIe link is down or in training, assigning a value of 0 to the configuration address can prevent read-write behavior to the configuration space of peripheral PCIe devices, thereby preventing kernel panic.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= e8635b484f644c7873e6091f15330c49396f2cbc < 6bff05aaa32c2f7e1f6e68e890876642159db4196bff05aaa32c2f7e1f6e68e890876642159db419
linuxlinux>= e8635b484f644c7873e6091f15330c49396f2cbc < 64845ac64819683ad5e51b668b2ed56ee3386aee64845ac64819683ad5e51b668b2ed56ee3386aee
linuxlinux>= e8635b484f644c7873e6091f15330c49396f2cbc < 6c1b9fe148a4e03bbfa234267ebb89f35285814a6c1b9fe148a4e03bbfa234267ebb89f35285814a
linuxlinux>= e8635b484f644c7873e6091f15330c49396f2cbc < 25998f5613159fe35920dbd484fcac7ea3ad079925998f5613159fe35920dbd484fcac7ea3ad0799
linuxlinux>= e8635b484f644c7873e6091f15330c49396f2cbc < d996deb80398a90dd3c03590e68dad543da87d62d996deb80398a90dd3c03590e68dad543da87d62
linuxlinux>= e8635b484f644c7873e6091f15330c49396f2cbc < 1c33fd17383f48f679186c54df78542106deeaa01c33fd17383f48f679186c54df78542106deeaa0
linuxlinux>= e8635b484f644c7873e6091f15330c49396f2cbc < 38d647d509543e9434b3cc470b914348be271fe938d647d509543e9434b3cc470b914348be271fe9
linuxlinux>= e8635b484f644c7873e6091f15330c49396f2cbc < 29b83a64df3b42c88c0338696feb6fdcd7f1f3b729b83a64df3b42c88c0338696feb6fdcd7f1f3b7
linuxlinux_kernel< 4.19.3174.19.317
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 4.20 < 5.4.2795.4.279
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.966.1.96
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221
linuxlinux_kernel>= 6.2 < 6.6.366.6.36
linuxlinux_kernel>= 6.7 < 6.9.76.9.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.