cbcvebase.
CVE-2024-47696
published 2024-10-21

CVE-2024-47696: In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency In the commit…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency In the commit aee2424246f9 ("RDMA/iwcm: Fix a use-after-free related to destroying CM IDs"), the function flush_workqueue is invoked to flush the work queue iwcm_wq. But at that time, the work queue iwcm_wq was created via the function alloc_ordered_workqueue without the flag WQ_MEM_RECLAIM. Because the current process is trying to flush the whole iwcm_wq, if iwcm_wq doesn't have the flag WQ_MEM_RECLAIM, verify that the current process is not reclaiming memory or running on a workqueue which doesn't have the flag WQ_MEM_RECLAIM as that can break forward-progress guarantee leading to a deadlock. The call trace is as below: [ 125.350876][ T1430] Call Trace: [ 125.356281][ T1430] [ 125.361285][ T1430] ? __warn (kernel/panic.c:693) [ 125.367640][ T1430] ? check_flush_dependency (kernel/workqueue.c:3706 (discriminator 9)) [ 125.375689][ T1430] ? report_bug (lib/bug.c:180 lib/bug.c:219) [ 125.382505][ T1430] ? handle_bug (arch/x86/kernel/traps.c:239) [ 125.388987][ T1430] ? exc_invalid_op (arch/x86/kernel/traps.c:260 (discriminator 1)) [ 125.395831][ T1430] ? asm_exc_invalid_op (arch/x86/include/asm/idtentry.h:621) [ 125.403125][ T1430] ? check_flush_dependency (kernel/workqueue.c:3706 (discriminator 9)) [ 125.410984][ T1430] ? check_flush_dependency (kernel/workqueue.c:3706 (discriminator 9)) [ 125.418764][ T1430] __flush_workqueue (kernel/workqueue.c:3970) [ 125.426021][ T1430] ? __pfx___might_resched (kernel/sched/core.c:10151) [ 125.433431][ T1430] ? destroy_cm_id (drivers/infiniband/core/iwcm.c:375) iw_cm [ 125.441209][ T1430] ? __pfx___flush_workqueue (kernel/workqueue.c:3910) [ 125.473900][ T1430] ? _raw_spin_lock_irqsave (arch/x86/include/asm/atomic.h:107 include/linux/atomic/atomic-arch-fallback.h:2170 include/linux/atomic/atomic-instrumented.h:1302 include/asm-generic/qspinlock.h:111 include/linux/spinlock.h:187 include/l

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 4.19.320 < 4.19.3234.19.323
linuxlinux>= 5.10.224 < 5.10.2275.10.227
linuxlinux>= 5.15.165 < 5.15.1685.15.168
linuxlinux>= 5.4.282 < 5.4.2855.4.285
linuxlinux>= 557d035fe88d78dd51664f4dc0e1896c04c97cf6 < da0392698c62397c19deb1b9e9bdf2fbb5a9420eda0392698c62397c19deb1b9e9bdf2fbb5a9420e
linuxlinux>= 6.1.103 < 6.1.1136.1.113
linuxlinux>= 6.10.3 < 6.10.136.10.13
linuxlinux>= 6.6.44 < 6.6.546.6.54
linuxlinux>= 7f25f296fc9bd0435be14e89bf657cd615a23574 < 29b3bbd912b8db86df7a3c180b910ccb621f563529b3bbd912b8db86df7a3c180b910ccb621f5635
linuxlinux>= 94ee7ff99b87435ec63211f632918dc7f44dac79 < 2efe8da2ddbf873385b4bc55366d09350b408df62efe8da2ddbf873385b4bc55366d09350b408df6
linuxlinux>= aee2424246f9f1dadc33faa78990c1e2eb7826e4 < a09dc967b3c58899e259c0aea092f421d22a0b04a09dc967b3c58899e259c0aea092f421d22a0b04
linuxlinux>= aee2424246f9f1dadc33faa78990c1e2eb7826e4 < 86dfdd8288907f03c18b7fb462e0e232c4f98d8986dfdd8288907f03c18b7fb462e0e232c4f98d89
linuxlinux>= d91d253c87fd1efece521ff2612078a35af673c6 < da2708a19f45b4a7278adf523837c8db21d1e2b5da2708a19f45b4a7278adf523837c8db21d1e2b5
linuxlinux>= dc8074b8901caabb97c2d353abd6b4e7fa5a59a5 < a64f30db12bdc937c5108158d98c8eab1925c548a64f30db12bdc937c5108158d98c8eab1925c548
linuxlinux>= ee39384ee787e86e9db4efb843818ef0ea9cb8ae < c8b18a75282cfd27822a8cc3c1f005c1ac8d1a58c8b18a75282cfd27822a8cc3c1f005c1ac8d1a58
linuxlinux>= ff5bbbdee08287d75d72e65b72a2b76d9637892a < 8b7df76356d098f85f3bd2c7cf6fb43f531893d78b7df76356d098f85f3bd2c7cf6fb43f531893d7
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.