cbcvebase.
CVE-2024-40995
published 2024-07-12

CVE-2024-40995: In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() syzbot found…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.1th percentile
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() syzbot found hanging tasks waiting on rtnl_lock [1] A reproducer is available in the syzbot bug. When a request to add multiple actions with the same index is sent, the second request will block forever on the first request. This holds rtnl_lock, and causes tasks to hang. Return -EAGAIN to prevent infinite looping, while keeping documented behavior. [1] INFO: task kworker/1:0:5088 blocked for more than 143 seconds. Not tainted 6.9.0-rc4-syzkaller-00173-g3cdb45594619 #0 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kworker/1:0 state:D stack:23744 pid:5088 tgid:5088 ppid:2 flags:0x00004000 Workqueue: events_power_efficient reg_check_chans_work Call Trace: context_switch kernel/sched/core.c:5409 [inline] __schedule+0xf15/0x5d00 kernel/sched/core.c:6746 __schedule_loop kernel/sched/core.c:6823 [inline] schedule+0xe7/0x350 kernel/sched/core.c:6838 schedule_preempt_disabled+0x13/0x30 kernel/sched/core.c:6895 __mutex_lock_common kernel/locking/mutex.c:684 [inline] __mutex_lock+0x5b8/0x9c0 kernel/locking/mutex.c:752 wiphy_lock include/net/cfg80211.h:5953 [inline] reg_leave_invalid_chans net/wireless/reg.c:2466 [inline] reg_check_chans_work+0x10a/0x10e0 net/wireless/reg.c:2481

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 0190c1d452a91c38a3462abdd81752be1b9006a8 < 0d8a2d287c8a394c0d4653f0c6c7be4c688e5a740d8a2d287c8a394c0d4653f0c6c7be4c688e5a74
linuxlinux>= 0190c1d452a91c38a3462abdd81752be1b9006a8 < c6a7da65a296745535a964be1019ec7691b0cb90c6a7da65a296745535a964be1019ec7691b0cb90
linuxlinux>= 0190c1d452a91c38a3462abdd81752be1b9006a8 < 25987a97eec4d5f897cd04ee1b45170829c610da25987a97eec4d5f897cd04ee1b45170829c610da
linuxlinux>= 0190c1d452a91c38a3462abdd81752be1b9006a8 < 6fc78d67f51aeb9a542d39a8714e16bc411582d46fc78d67f51aeb9a542d39a8714e16bc411582d4
linuxlinux>= 0190c1d452a91c38a3462abdd81752be1b9006a8 < 5f926aa96b08b6c47178fe1171e7ae331c695fc25f926aa96b08b6c47178fe1171e7ae331c695fc2
linuxlinux>= 0190c1d452a91c38a3462abdd81752be1b9006a8 < 7a0e497b597df7c4cf2b63fc6e9188b6cabe53357a0e497b597df7c4cf2b63fc6e9188b6cabe5335
linuxlinux>= 0190c1d452a91c38a3462abdd81752be1b9006a8 < d864319871b05fadd153e0aede4811ca7008f5d6d864319871b05fadd153e0aede4811ca7008f5d6
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 4.19 < 5.4.2795.4.279
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.966.1.96
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221
linuxlinux_kernel>= 6.2 < 6.6.366.6.36
linuxlinux_kernel>= 6.7 < 6.9.76.9.7
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.