cbcvebase.
CVE-2024-44995
published 2024-09-04

CVE-2024-44995: In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix a deadlock problem when config TC during resetting When config TC during the…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix a deadlock problem when config TC during resetting When config TC during the reset process, may cause a deadlock, the flow is as below: pf reset start │ ▼ ...... setup tc │ │ ▼ ▼ DOWN: napi_disable() napi_disable()(skip) │ │ │ ▼ ▼ ...... ...... │ │ ▼ │ napi_enable() │ ▼ UINIT: netif_napi_del() │ ▼ ...... │ ▼ INIT: netif_napi_add() │ ▼ ...... global reset start │ │ ▼ ▼ UP: napi_enable()(skip) ...... │ │ ▼ ▼ ...... napi_disable() In reset process, the driver will DOWN the port and then UINIT, in this case, the setup tc process will UP the port before UINIT, so cause the problem. Adds a DOWN process in UINIT to fix it.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= bb6b94a896d4dd4dcdeccca87c3fd22521c652c0 < 67492d4d105c0a6321b00c393eec96b9a7a97a1667492d4d105c0a6321b00c393eec96b9a7a97a16
linuxlinux>= bb6b94a896d4dd4dcdeccca87c3fd22521c652c0 < fc250eca15bde34c4c8f806b9d88f55bd56a992cfc250eca15bde34c4c8f806b9d88f55bd56a992c
linuxlinux>= bb6b94a896d4dd4dcdeccca87c3fd22521c652c0 < 195918217448a6bb7f929d6a2ffffce9f1ece1cc195918217448a6bb7f929d6a2ffffce9f1ece1cc
linuxlinux>= bb6b94a896d4dd4dcdeccca87c3fd22521c652c0 < 6ae2b7d63cd056f363045eb65409143e16f23ae86ae2b7d63cd056f363045eb65409143e16f23ae8
linuxlinux>= bb6b94a896d4dd4dcdeccca87c3fd22521c652c0 < fa1d4de7265c370e673583ac8d1bd17d21826cd9fa1d4de7265c370e673583ac8d1bd17d21826cd9
linuxlinux>= bb6b94a896d4dd4dcdeccca87c3fd22521c652c0 < de37408d5c26fc4a296a28a0c96dcb814219bfa1de37408d5c26fc4a296a28a0c96dcb814219bfa1
linuxlinux>= bb6b94a896d4dd4dcdeccca87c3fd22521c652c0 < be5e816d00a506719e9dbb1a9c861c5ced30a109be5e816d00a506719e9dbb1a9c861c5ced30a109
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 6.10.7-16.10.7-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 4.15 < 5.4.2835.4.283
linuxlinux_kernel>= 5.11 < 5.15.1665.15.166
linuxlinux_kernel>= 5.16 < 6.1.1076.1.107
linuxlinux_kernel>= 5.5 < 5.10.2255.10.225
linuxlinux_kernel>= 6.2 < 6.6.486.6.48

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.