CVE-2024-43866Race Condition in Linux

Severity
4.7MEDIUMNVD
OSV5.5
EPSS
0.0%
top 96.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 21
Latest updateJan 9

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Always drain health in shutdown callback There is no point in recovery during device shutdown. if health work started need to wait for it to avoid races and NULL pointer access. Hence, drain health WQ on shutdown callback.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages6 packages

NVDlinux/linux_kernel4.13.166.1.113+3
Debianlinux/linux_kernel< 6.1.115-1+2
Ubuntulinux/linux_kernel< 6.8.0-50.51
CVEListV5linux/linuxd2aa060d40fa060e963f9a356d43481e43ba3dac5005e2e159b300c1b8c6820a1e13a62eb0127b9b+5
debiandebian/linux< linux 6.1.115-1 (bookworm)

Patches

🔴Vulnerability Details

7
OSV
linux-azure, linux-azure-6.8 vulnerabilities2025-01-09
OSV
linux-hwe-6.8 vulnerabilities2025-01-06
OSV
linux-gkeop vulnerabilities2024-12-12
OSV
linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency vulnerabilities2024-12-12
OSV
linux, linux-aws, linux-aws-6.8, linux-gcp, linux-gcp-6.8, linux-gke, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oem-6.8, linux-oracle, linux-oracle-6.8, linux-raspi vulnerabilities2024-12-12

📋Vendor Advisories

7
Ubuntu
Linux kernel (Azure) vulnerabilities2025-01-09
Ubuntu
Linux kernel (HWE) vulnerabilities2025-01-06
Ubuntu
Linux kernel (GKE) vulnerabilities2024-12-12
Ubuntu
Linux kernel (NVIDIA) vulnerabilities2024-12-12
Ubuntu
Linux kernel vulnerabilities2024-12-12