cbcvebase.
CVE-2024-58071
published 2025-03-06

CVE-2024-58071: In the Linux kernel, the following vulnerability has been resolved: team: prevent adding a device which is already a team device lower Prevent adding a device…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.3th percentile
In the Linux kernel, the following vulnerability has been resolved: team: prevent adding a device which is already a team device lower Prevent adding a device which is already a team device lower, e.g. adding veth0 if vlan1 was already added and veth0 is a lower of vlan1. This is not useful in practice and can lead to recursive locking: $ ip link add veth0 type veth peer name veth1 $ ip link set veth0 up $ ip link set veth1 up $ ip link add link veth0 name veth0.1 type vlan protocol 802.1Q id 1 $ ip link add team0 type team $ ip link set veth0.1 down $ ip link set veth0.1 master team0 team0: Port device veth0.1 added $ ip link set veth0 down $ ip link set veth0 master team0 WARNING: possible recursive locking detected 6.13.0-rc2-virtme-00441-ga14a429069bb #46 Not tainted ip/7684 is trying to acquire lock: ffff888016848e00 (team->team_lock_key){+.+.}-{4:4}, at: team_device_event (drivers/net/team/team_core.c:2928 drivers/net/team/team_core.c:2951 drivers/net/team/team_core.c:2973) but task is already holding lock: ffff888016848e00 (team->team_lock_key){+.+.}-{4:4}, at: team_add_slave (drivers/net/team/team_core.c:1147 drivers/net/team/team_core.c:1977) other info that might help us debug this: Possible unsafe locking scenario: CPU0 ---- lock(team->team_lock_key); lock(team->team_lock_key); *** DEADLOCK *** May be due to missing lock nesting notation 2 locks held by ip/7684: stack backtrace: CPU: 3 UID: 0 PID: 7684 Comm: ip Not tainted 6.13.0-rc2-virtme-00441-ga14a429069bb #46 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: dump_stack_lvl (lib/dump_stack.c:122) print_deadlock_bug.cold (kernel/locking/lockdep.c:3040) __lock_acquire (kernel/locking/lockdep.c:3893 kernel/locking/lockdep.c:5226) ? netlink_broadcast_filtered (net/netlink/af_netlink.c:1548) lock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5851) ? team_device_event (drivers/net/team/team_core.c:2928 drivers/net/t

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= 3d249d4ca7d0ed6629a135ea1ea21c72286c0d80 < 0a7794b9ca78c8e7d001c583bf05736169de3f200a7794b9ca78c8e7d001c583bf05736169de3f20
linuxlinux>= 3d249d4ca7d0ed6629a135ea1ea21c72286c0d80 < 62ff1615815d565448c37cb8a7a2a076492ec47162ff1615815d565448c37cb8a7a2a076492ec471
linuxlinux>= 3d249d4ca7d0ed6629a135ea1ea21c72286c0d80 < bd099a2fa9be983ba0e90a57a59484fe9d520ba8bd099a2fa9be983ba0e90a57a59484fe9d520ba8
linuxlinux>= 3d249d4ca7d0ed6629a135ea1ea21c72286c0d80 < adff6ac889e16d97abd1e4543f533221127e978aadff6ac889e16d97abd1e4543f533221127e978a
linuxlinux>= 3d249d4ca7d0ed6629a135ea1ea21c72286c0d80 < 184a564e6000b41582f160a5be9a9b5aabe22ac1184a564e6000b41582f160a5be9a9b5aabe22ac1
linuxlinux>= 3d249d4ca7d0ed6629a135ea1ea21c72286c0d80 < 1bb06f919fa5bec77ad9b6002525c3dcc5c1fd6c1bb06f919fa5bec77ad9b6002525c3dcc5c1fd6c
linuxlinux>= 3d249d4ca7d0ed6629a135ea1ea21c72286c0d80 < d9bce1310c0e2a55888e3e08c9f69d8377b3a377d9bce1310c0e2a55888e3e08c9f69d8377b3a377
linuxlinux>= 3d249d4ca7d0ed6629a135ea1ea21c72286c0d80 < 3fff5da4ca2164bb4d0f1e6cd33f6eb8a0e73e503fff5da4ca2164bb4d0f1e6cd33f6eb8a0e73e50
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 3.3 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1296.1.129
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.26.13.2
linuxlinux_kernel>= 6.2 < 6.6.766.6.76
linuxlinux_kernel>= 6.7 < 6.12.136.12.13

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.